Compare commits
23
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
b8b8b78b09 | ||
|
|
289016d071 | ||
|
|
4b2b192601 | ||
|
|
993befdedd | ||
|
|
abaf5d9c10 | ||
|
|
67f4ff931e | ||
|
|
295a575b15 | ||
|
|
bf5f2508b8 | ||
|
|
45ca5057f8 | ||
|
|
8b41f64e12 | ||
|
|
1b01847c66 | ||
|
|
0af0124e17 | ||
|
|
e34289fdb5 | ||
|
|
471b8221ff | ||
|
|
64f98990c8 | ||
|
|
306b601490 | ||
|
|
b3d71724ae | ||
|
|
a1ac7ea8d5 | ||
|
|
bbf6744444 | ||
|
|
e0fe47d5a9 | ||
|
|
4a844ac6fa | ||
|
|
b74ed17823 | ||
|
|
8973e5dc19 |
+12
@@ -118,6 +118,18 @@ pub struct Cli {
|
||||
/// or if the previously saved test result is stale.
|
||||
#[arg(long)]
|
||||
pub reconfigure: bool,
|
||||
|
||||
/// Run the read-only audio-exclusion dry-run audit against the live
|
||||
/// PipeWire graph, then exit on ctrl-c. Emits one JSON object per line to
|
||||
/// stderr (or to `PIXELPASS_AUDIO_AUDIT_FILE`) describing which audio
|
||||
/// streams would be eligible for a screen share and why the rest would not.
|
||||
/// Creates no links and changes no routing.
|
||||
///
|
||||
/// Hidden: this is development instrumentation for the screen-share audio
|
||||
/// exclusion work (impl plan phase 5), not a user-facing feature, and the
|
||||
/// record schema is free to change until phase 6 fixes it.
|
||||
#[arg(long, hide = true)]
|
||||
pub audit_audio: bool,
|
||||
}
|
||||
|
||||
#[derive(ValueEnum, Clone, Copy, Debug)]
|
||||
|
||||
@@ -1,5 +1,15 @@
|
||||
use anyhow::{Context, Result};
|
||||
use tokio::signal::unix::{Signal, SignalKind};
|
||||
use tokio_util::sync::CancellationToken;
|
||||
|
||||
/// A stream of SIGTERMs, for the callers that need to shut down cleanly when
|
||||
/// something other than a human at a terminal asks them to (`timeout`, a test
|
||||
/// harness, a service manager). Ctrl-c alone covers only the interactive case.
|
||||
pub fn terminate_stream() -> Result<Signal> {
|
||||
tokio::signal::unix::signal(SignalKind::terminate())
|
||||
.context("could not install a SIGTERM handler")
|
||||
}
|
||||
|
||||
/// Install a ctrl-c handler that triggers the returned token.
|
||||
///
|
||||
/// The first ctrl-c cancels gracefully; a second ctrl-c terminates the process.
|
||||
|
||||
@@ -0,0 +1,311 @@
|
||||
//! Phase 4 — the AEC identity validation state machine (impl plan §4, design
|
||||
//! v3.4 §5.2/§5.3).
|
||||
//!
|
||||
//! peerspeak's echo canceller (`module-echo-cancel`) creates four graph nodes
|
||||
//! that all carry `pulse.module.id == <the index pactl returned>`, and the
|
||||
//! playback leg among them is a `Stream/Output/Audio` node wired straight to
|
||||
//! the speakers — a fan-out candidate that would copy the whole remote call
|
||||
//! into the share unless it is excluded (v3.4 §5.2, measured ≈desktop level).
|
||||
//! The taint engine (phase 2) already excludes it *given* the module index in
|
||||
//! [`ExclusionCtx::aec_module_id`](crate::host::taint::ExclusionCtx); this
|
||||
//! module is what decides, at runtime and fail-closed, whether that index may
|
||||
//! be trusted and handed over.
|
||||
//!
|
||||
//! **Why a state machine and not a one-shot check (v3.4 §5.3).** The identity
|
||||
//! is an *observed correlation on PipeWire 1.6.8*, not a documented contract,
|
||||
//! and a start-time enumeration races in both directions: peerspeak's
|
||||
//! `enable()` returns before the playback hazard leg is even in the graph, and
|
||||
//! pixelpass's capture spawns lazily on the first viewer, at a moment peerspeak
|
||||
//! does not control. So validation is a bounded epoch, and the identity can be
|
||||
//! *lost* mid-share (the module unloads) as well as *gained*.
|
||||
//!
|
||||
//! **The two traps this is shaped around:**
|
||||
//!
|
||||
//! - **Revocation is loss of the whole module identity, not one leg corking**
|
||||
//! (v3.4 §5.3). Each [`AecValidator::observe`] rescans the snapshot for *any*
|
||||
//! node bearing the index; [`AecState::Validated`] drops to
|
||||
//! [`AecState::Revoked`] only when that set becomes **empty**. A single leg
|
||||
//! corking or relinking (still ≥1 present) stays `Validated` — getting this
|
||||
//! wrong turns a normal cork into a spurious share-wide audio stop.
|
||||
//! - **Module indices are reused verbatim across unload/reload** (v3.4 §5.2
|
||||
//! correction 3 — both a reload's module index *and* its `node.link-group`
|
||||
//! came back byte-identical, and node ids were recycled *and reassigned
|
||||
//! across legs*). So [`AecState::Failed`] and [`AecState::Revoked`] are
|
||||
//! **sticky terminal**: a later node reappearing with the same index does
|
||||
//! **not** un-revoke and alias onto the new module. A genuine reload gets a
|
||||
//! *fresh* [`AecValidator`] (peerspeak re-tells pixelpass the index on every
|
||||
//! load), never a resurrected one.
|
||||
//!
|
||||
//! **Scope.** This is the validation state machine + `--aec` parsing only.
|
||||
//! Foreign / second-AEC detection (a non-owned `echo-cancel-*` group, v3.4
|
||||
//! §5.4 / D3) and the `foreign_aec_warning`/`aec_failed`/`aec_revoked` status
|
||||
//! *events* are phase 6's, which reads this machine's [`AecState`]. Wiring the
|
||||
//! parsed [`AecConfig`] out of the CLI and calling [`AecValidator::observe`]
|
||||
//! in the recompute loop is integration (phases 5/8). The node-side
|
||||
//! `pulse.module.id` parse (JSON-number-vs-string, u64-not-u32) is phase 3's
|
||||
//! adapter; this module consumes the already-parsed
|
||||
//! [`NodeProps::pulse_module_id`](crate::host::taint::snapshot::NodeProps).
|
||||
|
||||
#![allow(dead_code)] // Wired into `--aec` parsing + the recompute loop by later phases.
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests;
|
||||
|
||||
use crate::host::observer::Millis;
|
||||
use crate::host::taint::snapshot::GraphSnapshot;
|
||||
|
||||
/// The parsed `--aec=off|pulse-module:<idx>` argument (decision D5).
|
||||
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
|
||||
pub enum AecConfig {
|
||||
/// `--aec=off` — peerspeak's AEC is not in play, so there is nothing to
|
||||
/// exclude and fan-out proceeds with no AEC identity. Not the same as an
|
||||
/// *absent* argument (that default is the caller's; see [`parse_aec_arg`]).
|
||||
Off,
|
||||
/// `--aec=pulse-module:<idx>` — validate this live module index before
|
||||
/// trusting it. The index is compared as `u64`, never `u32` (v3.4 §5.2).
|
||||
PulseModule(u64),
|
||||
}
|
||||
|
||||
/// Why an `--aec` argument was rejected. Rejection is fatal at the CLI edge —
|
||||
/// there is no fail-closed *default* index, because a wrong index would exclude
|
||||
/// the wrong node (or nothing), so a malformed value must not silently become
|
||||
/// "no AEC".
|
||||
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
|
||||
pub enum AecParseError {
|
||||
/// The value was empty.
|
||||
Empty,
|
||||
/// Not `off` and not `pulse-module:...`.
|
||||
UnknownForm,
|
||||
/// `pulse-module:` with nothing after the colon.
|
||||
MissingIndex,
|
||||
/// The index was not a bare `u64` decimal (sign, whitespace, non-digit, or
|
||||
/// `> u64::MAX`).
|
||||
InvalidIndex,
|
||||
}
|
||||
|
||||
/// Parse one `--aec` value. `off` and `pulse-module:<idx>` are the only forms.
|
||||
///
|
||||
/// The index accepts values `> u32::MAX` (v3.4 §5.2: `pulse.module.id` sits
|
||||
/// next to the `object.serial` u32-truncation bug, so it is only ever compared
|
||||
/// as `u64`) and requires a **bare decimal** — stricter than Rust's [`u64`]
|
||||
/// parser, which also accepts a leading `+`. Rejected: any sign, surrounding or
|
||||
/// interior whitespace, non-decimal digits, and overflow. Matching is exact and
|
||||
/// case-sensitive: the argument is machine-generated by peerspeak from
|
||||
/// `EchoCancelGuard::module_index`, not typed by a user.
|
||||
///
|
||||
/// ⚠️ **Producer contract** (Codex phase-4 review, finding 5): because the
|
||||
/// grammar is narrower than Rust's parser, peerspeak must emit a bare decimal.
|
||||
/// `pactl load-module` returns an unsigned decimal, so the stored index is
|
||||
/// already canonical and no reachable value is rejected; if peerspeak ever
|
||||
/// changes how it formats the index it must canonicalize (`value.to_string()`),
|
||||
/// not widen this parser — the narrow grammar is the point.
|
||||
pub fn parse_aec_arg(value: &str) -> Result<AecConfig, AecParseError> {
|
||||
if value.is_empty() {
|
||||
return Err(AecParseError::Empty);
|
||||
}
|
||||
if value == "off" {
|
||||
return Ok(AecConfig::Off);
|
||||
}
|
||||
if let Some(index) = value.strip_prefix("pulse-module:") {
|
||||
if index.is_empty() {
|
||||
return Err(AecParseError::MissingIndex);
|
||||
}
|
||||
// A bare decimal only: reject a leading sign (Rust's `u64` parser
|
||||
// accepts `+7`), interior/surrounding whitespace, and any non-digit,
|
||||
// before letting the parser catch overflow. Leading zeros are harmless.
|
||||
if !index.bytes().all(|b| b.is_ascii_digit()) {
|
||||
return Err(AecParseError::InvalidIndex);
|
||||
}
|
||||
return index
|
||||
.parse::<u64>()
|
||||
.map(AecConfig::PulseModule)
|
||||
.map_err(|_| AecParseError::InvalidIndex);
|
||||
}
|
||||
Err(AecParseError::UnknownForm)
|
||||
}
|
||||
|
||||
/// The validation epoch (v3.4 §5.3, verbatim).
|
||||
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
|
||||
pub enum AecState {
|
||||
/// `--aec=off` — no AEC identity, fan-out proceeds with no exclusion.
|
||||
/// Terminal.
|
||||
NotConfigured,
|
||||
/// Waiting for the first node bearing the index. **No fan-out occurs here**
|
||||
/// — silence is the safe direction. Ends at `Validated` on first sight, or
|
||||
/// `Failed` once the graph is fully enumerated and the bounded deadline
|
||||
/// passes with the index never seen.
|
||||
Validating,
|
||||
/// The index was observed live. Fan-out is permitted, excluding that
|
||||
/// identity transitively (phase 2 / v3.4 §6.1).
|
||||
Validated,
|
||||
/// The deadline expired with the index never observed. **Fail closed** — no
|
||||
/// fan-out; the caller reports a capability failure rather than sharing.
|
||||
/// Sticky terminal.
|
||||
Failed,
|
||||
/// The whole module identity disappeared mid-share (every node bearing the
|
||||
/// index gone). **Stop fan-out now** and drop the owned link proxies; do
|
||||
/// not keep the numeric index and hope, because it is reused. Sticky
|
||||
/// terminal — see the module header's second trap.
|
||||
Revoked,
|
||||
}
|
||||
|
||||
/// The bounded, read-only AEC identity validator. Fold the live graph in with
|
||||
/// [`AecValidator::observe`] once per recompute; read the result with
|
||||
/// [`AecValidator::state`], [`AecValidator::fan_out_permitted`], and
|
||||
/// [`AecValidator::validated_module_id`].
|
||||
#[derive(Clone, Debug)]
|
||||
pub struct AecValidator {
|
||||
/// The index to validate. `None` iff [`AecConfig::Off`] (state stays
|
||||
/// [`AecState::NotConfigured`] forever).
|
||||
target: Option<u64>,
|
||||
state: AecState,
|
||||
/// The `Validating → Failed` budget, applied *after* the deadline is armed.
|
||||
timeout: Millis,
|
||||
/// The absolute `Failed` deadline, armed the first time the graph reports
|
||||
/// ready (the "registry sync barrier" of v3.4 §5.3) and never re-armed —
|
||||
/// `graph_ready` is dynamic and can flap, but the epoch budget must not
|
||||
/// restart. `None` until then: while the initial enumeration is still in
|
||||
/// flight, a not-yet-seen index is *unknown*, not *absent*, so it must not
|
||||
/// time out to `Failed`.
|
||||
deadline: Option<Millis>,
|
||||
}
|
||||
|
||||
impl AecValidator {
|
||||
/// `timeout` is the `Validating → Failed` budget, counted from the moment
|
||||
/// the graph first becomes ready (not from construction). An `Off` config
|
||||
/// starts (and stays) [`AecState::NotConfigured`].
|
||||
pub fn new(config: AecConfig, timeout: Millis) -> Self {
|
||||
match config {
|
||||
AecConfig::Off => Self {
|
||||
target: None,
|
||||
state: AecState::NotConfigured,
|
||||
timeout,
|
||||
deadline: None,
|
||||
},
|
||||
AecConfig::PulseModule(index) => Self {
|
||||
target: Some(index),
|
||||
state: AecState::Validating,
|
||||
timeout,
|
||||
deadline: None,
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
pub fn state(&self) -> AecState {
|
||||
self.state
|
||||
}
|
||||
|
||||
/// The validated index to place in
|
||||
/// [`ExclusionCtx::aec_module_id`](crate::host::taint::ExclusionCtx) —
|
||||
/// `Some` **only** in [`AecState::Validated`]. `None` everywhere else,
|
||||
/// including `NotConfigured` (no AEC ⇒ nothing to exclude) and the
|
||||
/// fail-closed states (whose `None` must be paired with
|
||||
/// [`Self::fan_out_permitted`] `== false`, i.e. no fan-out at all — *not*
|
||||
/// a fan-out that merely skips AEC exclusion).
|
||||
pub fn validated_module_id(&self) -> Option<u64> {
|
||||
match self.state {
|
||||
AecState::Validated => self.target,
|
||||
_ => None,
|
||||
}
|
||||
}
|
||||
|
||||
/// Whether fan-out may proceed at all right now. True only in
|
||||
/// [`AecState::NotConfigured`] (fan out, no exclusion) and
|
||||
/// [`AecState::Validated`] (fan out, excluding the identity). `Validating`,
|
||||
/// `Failed` and `Revoked` all forbid it — silence over echo.
|
||||
pub fn fan_out_permitted(&self) -> bool {
|
||||
matches!(self.state, AecState::NotConfigured | AecState::Validated)
|
||||
}
|
||||
|
||||
/// Fold one recompute's view of the graph into the machine.
|
||||
///
|
||||
/// `graph_ready` is the observer's dynamic readiness
|
||||
/// ([`Projection::graph_ready`](crate::host::observer::Projection)); `now`
|
||||
/// is a monotonic millisecond clock. Positive evidence (a node bearing the
|
||||
/// index) is authoritative and validates regardless of `graph_ready` —
|
||||
/// seeing the node *is* seeing it — but the `Failed` deadline only begins
|
||||
/// once `graph_ready` has first become true, so a slow initial enumeration
|
||||
/// can never masquerade as a genuinely-absent module.
|
||||
pub fn observe(&mut self, snapshot: &GraphSnapshot, graph_ready: bool, now: Millis) {
|
||||
// `Off` (NotConfigured) and both sticky terminals are no-ops: there is
|
||||
// nothing to look for, and a reappearing reused index must not revive a
|
||||
// Failed/Revoked epoch (v3.4 §5.2 correction 3).
|
||||
let Some(target) = self.target else {
|
||||
return;
|
||||
};
|
||||
match self.state {
|
||||
AecState::Validating => {
|
||||
// Presence is checked *before* the deadline on purpose: a
|
||||
// demonstrably-present identity validates regardless of the
|
||||
// clock, even if the node is first seen just past the deadline
|
||||
// (Codex phase-4 review, finding 2). The deadline only bounds
|
||||
// the wait for an identity that is never seen — seeing it, late
|
||||
// or not, is ground truth that the module exists, and excluding
|
||||
// a real echo leg is always the safe answer. (A `Failed` can
|
||||
// still pre-empt this when a `Tick`-only observation crosses the
|
||||
// deadline first; that only makes the machine *more* fail-closed,
|
||||
// never less.)
|
||||
if self.index_present(snapshot, target) {
|
||||
self.state = AecState::Validated;
|
||||
return;
|
||||
}
|
||||
// Arm the deadline once, on the first ready graph.
|
||||
if self.deadline.is_none() && graph_ready {
|
||||
self.deadline = Some(now.saturating_add(self.timeout));
|
||||
}
|
||||
if self.deadline.is_some_and(|deadline| now >= deadline) {
|
||||
self.state = AecState::Failed;
|
||||
}
|
||||
}
|
||||
AecState::Validated => {
|
||||
// Revocation is the whole identity gone (no node bears the
|
||||
// index), not one leg corking — see the module header.
|
||||
//
|
||||
// ⚠️ **Deliberately NOT gated on `graph_ready`** (Codex
|
||||
// phase-4 review, findings 1 + 4). Two forces pull opposite
|
||||
// ways and this is the resolution:
|
||||
//
|
||||
// - Gating revoke on readiness would avoid a *spurious* revoke
|
||||
// from a transient empty snapshot seen while the module is
|
||||
// still live. But for the AEC that transient does not exist:
|
||||
// its four nodes are two `Stream/*` legs plus a null-sink-like
|
||||
// virtual sink/source, none of which claim a `device.id`, so
|
||||
// the phase-3 observer never *withholds* them
|
||||
// (`observer::classify` withholds only device-claiming nodes).
|
||||
// `index_present` therefore goes false only on a genuine
|
||||
// `global_remove` of every leg — a real unload — and a real
|
||||
// unload *should* revoke.
|
||||
// - Worse, gating on readiness would REOPEN the reused-index
|
||||
// alias trap: if an unload+reload (indices recycle, §5.2
|
||||
// correction 3) both complete inside one not-ready churn
|
||||
// window, the ready snapshot would already show the *new*
|
||||
// module's node and we would never observe the empty gap —
|
||||
// silently aliasing onto an unrelated module. Revoking the
|
||||
// instant the gap appears, ready or not, is what closes it.
|
||||
//
|
||||
// This correctness rests on the phase-5/6 integration contract:
|
||||
// **one `observe` per graph event, no coalescing across a module
|
||||
// lifetime boundary.** Under coalescing, the empty gap between an
|
||||
// old unload and a reused-index reload can be skipped. The
|
||||
// robust fix that would not depend on that contract is a
|
||||
// serial-continuity / observer-generation signal (the AEC nodes'
|
||||
// `object.serial`s are fresh across a reload even when the index
|
||||
// is not) — owed to a later hardening round, not built here.
|
||||
if !self.index_present(snapshot, target) {
|
||||
self.state = AecState::Revoked;
|
||||
}
|
||||
}
|
||||
AecState::NotConfigured | AecState::Failed | AecState::Revoked => {}
|
||||
}
|
||||
}
|
||||
|
||||
/// Whether any node in the snapshot bears the target module index. The same
|
||||
/// exact-`u64`-equality predicate the taint engine roots on
|
||||
/// (`taint/mod.rs`), kept here so "is the identity live?" has one
|
||||
/// definition.
|
||||
fn index_present(&self, snapshot: &GraphSnapshot, target: u64) -> bool {
|
||||
snapshot
|
||||
.nodes()
|
||||
.any(|node| node.props.pulse_module_id == Some(target))
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,374 @@
|
||||
//! Phase 4 exit gate (impl plan §4): a fake-clock / event-sequence transition
|
||||
//! matrix, because these are timing semantics a live poke cannot cover.
|
||||
|
||||
use super::*;
|
||||
use crate::host::taint::snapshot::{
|
||||
GlobalId, GraphSnapshot, MediaRole, NodeProps, NodeSnapshot, Serial,
|
||||
};
|
||||
|
||||
/// A `Stream/Output/Audio` node carrying `pulse.module.id == module` (or none).
|
||||
/// Only the fields the validator reads matter; the rest take their defaults.
|
||||
fn node(serial: u64, module: Option<u64>) -> NodeSnapshot {
|
||||
NodeSnapshot {
|
||||
serial: Serial(serial),
|
||||
id: GlobalId(serial as u32),
|
||||
name: None,
|
||||
role: MediaRole::StreamOutput,
|
||||
props: NodeProps {
|
||||
pulse_module_id: module,
|
||||
..NodeProps::default()
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
/// A snapshot holding exactly the given nodes (no ports/links/clients — the
|
||||
/// validator reads only nodes).
|
||||
fn snapshot(nodes: Vec<NodeSnapshot>) -> GraphSnapshot {
|
||||
GraphSnapshot::new(nodes, vec![], vec![], vec![])
|
||||
}
|
||||
|
||||
fn empty() -> GraphSnapshot {
|
||||
snapshot(vec![])
|
||||
}
|
||||
|
||||
const IDX: u64 = 536_870_919; // 0x20000007 — a real pipewire-pulse module index.
|
||||
const TIMEOUT: Millis = 2_000;
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// Parsing (D5): off / pulse-module:<idx> / > u32::MAX / absent / malformed.
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
#[test]
|
||||
fn parses_off() {
|
||||
assert_eq!(parse_aec_arg("off"), Ok(AecConfig::Off));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parses_pulse_module_index() {
|
||||
assert_eq!(
|
||||
parse_aec_arg("pulse-module:536870919"),
|
||||
Ok(AecConfig::PulseModule(536_870_919)),
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn parses_index_beyond_u32() {
|
||||
// v3.4 §5.2: compare as u64, never u32. A value one past u32::MAX must
|
||||
// round-trip, not truncate or reject.
|
||||
let big = u64::from(u32::MAX) + 1;
|
||||
assert_eq!(
|
||||
parse_aec_arg(&format!("pulse-module:{big}")),
|
||||
Ok(AecConfig::PulseModule(big)),
|
||||
);
|
||||
assert_eq!(
|
||||
parse_aec_arg(&format!("pulse-module:{}", u64::MAX)),
|
||||
Ok(AecConfig::PulseModule(u64::MAX)),
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rejects_empty() {
|
||||
assert_eq!(parse_aec_arg(""), Err(AecParseError::Empty));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rejects_unknown_form() {
|
||||
assert_eq!(parse_aec_arg("on"), Err(AecParseError::UnknownForm));
|
||||
assert_eq!(parse_aec_arg("module:5"), Err(AecParseError::UnknownForm));
|
||||
assert_eq!(parse_aec_arg("536870919"), Err(AecParseError::UnknownForm));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rejects_missing_index() {
|
||||
assert_eq!(
|
||||
parse_aec_arg("pulse-module:"),
|
||||
Err(AecParseError::MissingIndex),
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rejects_malformed_index() {
|
||||
for bad in [
|
||||
"pulse-module:-1", // sign
|
||||
"pulse-module:+7", // sign
|
||||
"pulse-module: 7", // leading whitespace
|
||||
"pulse-module:7 ", // trailing whitespace
|
||||
"pulse-module:0x7", // hex
|
||||
"pulse-module:7.0", // non-integer
|
||||
"pulse-module:abc", // non-numeric
|
||||
"pulse-module:18446744073709551616", // u64::MAX + 1 (overflow)
|
||||
] {
|
||||
assert_eq!(
|
||||
parse_aec_arg(bad),
|
||||
Err(AecParseError::InvalidIndex),
|
||||
"{bad} should be InvalidIndex",
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// NotConfigured (--aec=off): benign, terminal, fan-out with no exclusion.
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
#[test]
|
||||
fn off_is_not_configured_and_permits_fan_out_with_no_identity() {
|
||||
let mut v = AecValidator::new(AecConfig::Off, TIMEOUT);
|
||||
assert_eq!(v.state(), AecState::NotConfigured);
|
||||
assert!(v.fan_out_permitted());
|
||||
assert_eq!(v.validated_module_id(), None);
|
||||
|
||||
// Even a snapshot full of module nodes never moves it off NotConfigured.
|
||||
v.observe(&snapshot(vec![node(1, Some(IDX))]), true, 10_000);
|
||||
assert_eq!(v.state(), AecState::NotConfigured);
|
||||
assert!(v.fan_out_permitted());
|
||||
assert_eq!(v.validated_module_id(), None);
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// Row: Validating → Validated on first matching node; no fan-out before.
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
#[test]
|
||||
fn validating_forbids_fan_out_and_exposes_no_identity() {
|
||||
let v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
assert_eq!(v.state(), AecState::Validating);
|
||||
assert!(!v.fan_out_permitted());
|
||||
assert_eq!(v.validated_module_id(), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn validating_to_validated_on_first_matching_node() {
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
// A node with a *different* index does not validate.
|
||||
v.observe(&snapshot(vec![node(1, Some(IDX + 1))]), true, 0);
|
||||
assert_eq!(v.state(), AecState::Validating);
|
||||
|
||||
v.observe(&snapshot(vec![node(2, Some(IDX))]), true, 100);
|
||||
assert_eq!(v.state(), AecState::Validated);
|
||||
assert!(v.fan_out_permitted());
|
||||
assert_eq!(v.validated_module_id(), Some(IDX));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn positive_evidence_validates_even_before_graph_ready() {
|
||||
// Seeing the node is authoritative; readiness only gates the Failed clock.
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
v.observe(&snapshot(vec![node(1, Some(IDX))]), false, 0);
|
||||
assert_eq!(v.state(), AecState::Validated);
|
||||
assert_eq!(v.validated_module_id(), Some(IDX));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn validated_index_is_compared_beyond_u32() {
|
||||
let big = u64::from(u32::MAX) + 7;
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(big), TIMEOUT);
|
||||
// A node whose id equals `big` only in its low 32 bits must not match.
|
||||
v.observe(
|
||||
&snapshot(vec![node(1, Some(big & u64::from(u32::MAX)))]),
|
||||
true,
|
||||
0,
|
||||
);
|
||||
assert_eq!(v.state(), AecState::Validating);
|
||||
|
||||
v.observe(&snapshot(vec![node(2, Some(big))]), true, 1);
|
||||
assert_eq!(v.state(), AecState::Validated);
|
||||
assert_eq!(v.validated_module_id(), Some(big));
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// Row: Validating → Failed on deadline expiry; and the deadline is armed only
|
||||
// once the graph is ready (the registry sync barrier).
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
#[test]
|
||||
fn validating_to_failed_on_deadline_expiry() {
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
v.observe(&empty(), true, 0); // arms deadline at 0 + 2000
|
||||
assert_eq!(v.state(), AecState::Validating);
|
||||
|
||||
v.observe(&empty(), true, TIMEOUT - 1);
|
||||
assert_eq!(v.state(), AecState::Validating);
|
||||
|
||||
v.observe(&empty(), true, TIMEOUT); // now >= deadline
|
||||
assert_eq!(v.state(), AecState::Failed);
|
||||
assert!(!v.fan_out_permitted());
|
||||
assert_eq!(v.validated_module_id(), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn deadline_is_not_armed_until_graph_ready() {
|
||||
// The whole point of arming-on-ready: a slow initial enumeration is
|
||||
// "unknown", not "absent", and must never time out to Failed.
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
// Long past the would-be deadline, but the graph has never been ready.
|
||||
v.observe(&empty(), false, 10 * TIMEOUT);
|
||||
assert_eq!(v.state(), AecState::Validating);
|
||||
// Still no Failed even much later, as long as ready stays false.
|
||||
v.observe(&empty(), false, 100 * TIMEOUT);
|
||||
assert_eq!(v.state(), AecState::Validating);
|
||||
|
||||
// And when readiness finally arrives, the FULL budget starts *there*, not
|
||||
// relative to construction (Codex phase-4 review, finding 3): a mutant that
|
||||
// armed a construction-relative deadline would fail immediately here.
|
||||
let late = 200_000;
|
||||
v.observe(&empty(), true, late); // first ready → arm at `late`
|
||||
assert_eq!(v.state(), AecState::Validating);
|
||||
v.observe(&empty(), true, late + TIMEOUT - 1);
|
||||
assert_eq!(v.state(), AecState::Validating);
|
||||
v.observe(&empty(), true, late + TIMEOUT);
|
||||
assert_eq!(v.state(), AecState::Failed);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn late_positive_evidence_wins_over_expired_deadline() {
|
||||
// A node first seen just past the deadline still validates: the deadline
|
||||
// only bounds the wait for an identity that is never seen, and a
|
||||
// demonstrably-present module is ground truth (Codex phase-4 review,
|
||||
// finding 2). Reachable only when the first post-deadline observation
|
||||
// carries the node with no intervening Tick-only observation.
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
v.observe(&empty(), true, 0); // arm deadline at 2000
|
||||
v.observe(&snapshot(vec![node(1, Some(IDX))]), true, TIMEOUT + 1);
|
||||
assert_eq!(v.state(), AecState::Validated);
|
||||
assert_eq!(v.validated_module_id(), Some(IDX));
|
||||
|
||||
// Whereas a Tick-only observation that crosses the deadline first pre-empts
|
||||
// it to Failed (stickily), even if the node then shows up — fail-closed.
|
||||
let mut w = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
w.observe(&empty(), true, 0);
|
||||
w.observe(&empty(), true, TIMEOUT); // Tick-only crosses the line first
|
||||
assert_eq!(w.state(), AecState::Failed);
|
||||
w.observe(&snapshot(vec![node(1, Some(IDX))]), true, TIMEOUT + 1);
|
||||
assert_eq!(w.state(), AecState::Failed);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn revokes_on_empty_even_while_not_ready() {
|
||||
// Revocation is deliberately NOT gated on graph_ready (Codex phase-4 review,
|
||||
// findings 1 + 4): the instant every node bearing the index is gone we
|
||||
// revoke, ready or not, because gating on readiness would let an
|
||||
// unload+reload that reused the index inside one not-ready churn window
|
||||
// silently alias onto the new module. A mutant adding `&& graph_ready` to
|
||||
// the revoke guard survives every other test but dies here.
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
v.observe(&snapshot(vec![node(1, Some(IDX))]), true, 0);
|
||||
assert_eq!(v.state(), AecState::Validated);
|
||||
v.observe(&empty(), false, 10); // identity gone during not-ready churn
|
||||
assert_eq!(v.state(), AecState::Revoked);
|
||||
assert!(!v.fan_out_permitted());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn deadline_armed_once_survives_ready_flapping() {
|
||||
// graph_ready is dynamic (it drops back to false while a Link is binding).
|
||||
// The epoch budget must be armed on the *first* ready and not restarted.
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
v.observe(&empty(), true, 1_000); // arm at 1000 → deadline 3000
|
||||
v.observe(&empty(), false, 2_000); // ready flaps off; must not disarm
|
||||
assert_eq!(v.state(), AecState::Validating);
|
||||
// At the original deadline it fails, even though ready is false now — the
|
||||
// budget did not restart from the flap.
|
||||
v.observe(&empty(), false, 3_000);
|
||||
assert_eq!(v.state(), AecState::Failed);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn failed_is_sticky_even_if_the_index_reappears() {
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
v.observe(&empty(), true, 0);
|
||||
v.observe(&empty(), true, TIMEOUT);
|
||||
assert_eq!(v.state(), AecState::Failed);
|
||||
|
||||
// A node bearing the index shows up late — must not resurrect the epoch.
|
||||
v.observe(&snapshot(vec![node(1, Some(IDX))]), true, TIMEOUT + 1);
|
||||
assert_eq!(v.state(), AecState::Failed);
|
||||
assert!(!v.fan_out_permitted());
|
||||
assert_eq!(v.validated_module_id(), None);
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// Row: partial-node disappearance ⇒ stays Validated; all gone ⇒ Revoked.
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
#[test]
|
||||
fn partial_leg_disappearance_stays_validated() {
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
// The module's four nodes all carry the index.
|
||||
let four = snapshot(vec![
|
||||
node(1, Some(IDX)),
|
||||
node(2, Some(IDX)),
|
||||
node(3, Some(IDX)),
|
||||
node(4, Some(IDX)),
|
||||
]);
|
||||
v.observe(&four, true, 0);
|
||||
assert_eq!(v.state(), AecState::Validated);
|
||||
|
||||
// Three legs cork/relink away; one still bears the index → still Validated.
|
||||
v.observe(&snapshot(vec![node(4, Some(IDX))]), true, 10);
|
||||
assert_eq!(v.state(), AecState::Validated);
|
||||
assert_eq!(v.validated_module_id(), Some(IDX));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn all_nodes_gone_revokes() {
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
v.observe(&snapshot(vec![node(1, Some(IDX))]), true, 0);
|
||||
assert_eq!(v.state(), AecState::Validated);
|
||||
|
||||
// The whole identity unloads: no node bears the index any more.
|
||||
v.observe(&empty(), true, 10);
|
||||
assert_eq!(v.state(), AecState::Revoked);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn revoked_stops_fan_out_and_exposes_no_identity() {
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
v.observe(&snapshot(vec![node(1, Some(IDX))]), true, 0);
|
||||
v.observe(&empty(), true, 10);
|
||||
assert_eq!(v.state(), AecState::Revoked);
|
||||
assert!(!v.fan_out_permitted());
|
||||
assert_eq!(v.validated_module_id(), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_node_that_merely_changes_index_revokes() {
|
||||
// Not a disappearance in the id sense, but the *identity* is gone: no node
|
||||
// bears our index any more, even though a same-serial node lingers.
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
v.observe(&snapshot(vec![node(1, Some(IDX))]), true, 0);
|
||||
v.observe(&snapshot(vec![node(1, Some(IDX + 1))]), true, 10);
|
||||
assert_eq!(v.state(), AecState::Revoked);
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// Row: a retained stale index does not alias onto a reloaded module — indices
|
||||
// ARE reused (v3.4 §5.2 correction 3). This is the sharpest safety property.
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
#[test]
|
||||
fn revoked_index_does_not_alias_onto_a_reloaded_module() {
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
v.observe(&snapshot(vec![node(1, Some(IDX))]), true, 0);
|
||||
v.observe(&empty(), true, 10);
|
||||
assert_eq!(v.state(), AecState::Revoked);
|
||||
|
||||
// A *different* module later reloads and pactl hands it the very same
|
||||
// index (measured: 536870919 came back verbatim). A resurrecting machine
|
||||
// would silently start excluding this unrelated module's node. Ours must
|
||||
// stay Revoked and fail closed; a real reload gets a fresh validator.
|
||||
v.observe(&snapshot(vec![node(99, Some(IDX))]), true, 20);
|
||||
assert_eq!(v.state(), AecState::Revoked);
|
||||
assert!(!v.fan_out_permitted());
|
||||
assert_eq!(v.validated_module_id(), None);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn a_fresh_validator_re_validates_the_reused_index() {
|
||||
// The counterpart: because peerspeak re-tells pixelpass the index on every
|
||||
// load, the correct response to a reload is a new machine, which validates
|
||||
// the reused index cleanly — proving stickiness costs nothing legitimate.
|
||||
let mut v = AecValidator::new(AecConfig::PulseModule(IDX), TIMEOUT);
|
||||
v.observe(&snapshot(vec![node(1, Some(IDX))]), true, 0);
|
||||
assert_eq!(v.state(), AecState::Validated);
|
||||
assert_eq!(v.validated_module_id(), Some(IDX));
|
||||
}
|
||||
@@ -0,0 +1,269 @@
|
||||
//! O5 measurement, pure (impl plan §5.2).
|
||||
//!
|
||||
//! v3.4 §6.4 asserts "a full recompute per graph event is fine for v1". The
|
||||
//! impl plan closes O5 by refusing to let that rest on a node count: what has
|
||||
//! to be recorded is the **graph-event rate**, the **recompute duration
|
||||
//! distribution and maximum**, and **whether events queue behind recompute or
|
||||
//! logging**.
|
||||
//!
|
||||
//! Everything here is arithmetic over samples the caller supplies. The clock
|
||||
//! reads live at the I/O edge ([`super::sink`]), which is what keeps the
|
||||
//! statistics unit-testable: a test feeds a hand-written sample sequence and
|
||||
//! asserts the summary exactly, with no timing flake.
|
||||
//!
|
||||
//! **The queueing measure is a proxy, and a one-directional one.** libpipewire
|
||||
//! dispatches registry callbacks serially on its own loop thread and exposes no
|
||||
//! queue depth, so nothing here can read a backlog directly. What it can see is
|
||||
//! that the observer thread was *continuously busy*: if an event begins being
|
||||
//! handled within [`QUEUE_THRESHOLD_US`] of the previous sample's completion,
|
||||
//! it was almost certainly already waiting while that recompute ran. That makes
|
||||
//! [`Summary::queued_events`] a **lower bound** — a genuine backlog always shows
|
||||
//! up in it, but a burst that happens to arrive exactly as the loop goes idle is
|
||||
//! counted as un-queued. Combined with [`Summary::busy_fraction`] (which needs
|
||||
//! no inference at all) it is enough to answer O5 in the direction that matters:
|
||||
//! a low busy fraction with zero queued events is headroom, and anything else is
|
||||
//! a number to argue about rather than an assumption to inherit.
|
||||
|
||||
use serde::Serialize;
|
||||
|
||||
use crate::host::observer::EventKind;
|
||||
|
||||
/// An event beginning this close behind the previous sample's completion is
|
||||
/// counted as having queued. Deliberately tight: the cost of being wrong in the
|
||||
/// generous direction is a metric that overstates backlog and sends a later
|
||||
/// round chasing a non-problem.
|
||||
pub const QUEUE_THRESHOLD_US: u64 = 100;
|
||||
|
||||
/// Upper bounds of the duration histogram, microseconds. A twelfth (overflow)
|
||||
/// bucket catches everything at or above the last bound. Log-ish spacing: the
|
||||
/// interesting question is which order of magnitude a recompute lands in, not
|
||||
/// its exact microsecond.
|
||||
pub const BUCKET_BOUNDS_US: [u64; 11] = [
|
||||
50, 100, 250, 500, 1_000, 2_500, 5_000, 10_000, 25_000, 50_000, 100_000,
|
||||
];
|
||||
|
||||
/// Human labels for the histogram buckets, parallel to [`BUCKET_BOUNDS_US`]
|
||||
/// plus the overflow bucket.
|
||||
pub const BUCKET_LABELS: [&str; 12] = [
|
||||
"<50us", "<100us", "<250us", "<500us", "<1ms", "<2.5ms", "<5ms", "<10ms", "<25ms", "<50ms",
|
||||
"<100ms", ">=100ms",
|
||||
];
|
||||
|
||||
/// A bucketed duration distribution with exact count, sum and maximum.
|
||||
///
|
||||
/// Bounded memory by construction — the audit runs for as long as a share does,
|
||||
/// and keeping every sample to compute an exact percentile would grow without
|
||||
/// limit. The maximum, which is the number O5 actually cares about, is kept
|
||||
/// exactly; percentiles are reported as the bucket they fall in.
|
||||
#[derive(Clone, Debug, Default, PartialEq, Eq)]
|
||||
pub struct Histogram {
|
||||
buckets: [u64; 12],
|
||||
count: u64,
|
||||
sum_us: u64,
|
||||
max_us: u64,
|
||||
}
|
||||
|
||||
impl Histogram {
|
||||
pub fn record(&mut self, us: u64) {
|
||||
let index = BUCKET_BOUNDS_US
|
||||
.iter()
|
||||
.position(|&bound| us < bound)
|
||||
.unwrap_or(BUCKET_BOUNDS_US.len());
|
||||
self.buckets[index] += 1;
|
||||
self.count += 1;
|
||||
self.sum_us = self.sum_us.saturating_add(us);
|
||||
self.max_us = self.max_us.max(us);
|
||||
}
|
||||
|
||||
pub fn count(&self) -> u64 {
|
||||
self.count
|
||||
}
|
||||
|
||||
pub fn max_us(&self) -> u64 {
|
||||
self.max_us
|
||||
}
|
||||
|
||||
pub fn sum_us(&self) -> u64 {
|
||||
self.sum_us
|
||||
}
|
||||
|
||||
pub fn mean_us(&self) -> Option<u64> {
|
||||
(self.count > 0).then(|| self.sum_us / self.count)
|
||||
}
|
||||
|
||||
/// The label of the bucket the `q`-quantile falls in (`q` in `0.0..=1.0`),
|
||||
/// or `None` when nothing has been recorded.
|
||||
///
|
||||
/// Uses the *nearest-rank* definition: the bucket containing the
|
||||
/// `ceil(q · count)`-th sample in ascending order. Reported as a bucket
|
||||
/// rather than a number because interpolating inside a bucket would invent
|
||||
/// precision the histogram does not have.
|
||||
pub fn quantile_bucket(&self, q: f64) -> Option<&'static str> {
|
||||
if self.count == 0 {
|
||||
return None;
|
||||
}
|
||||
let q = q.clamp(0.0, 1.0);
|
||||
// Rank is 1-based; q = 0 still names the bucket holding the smallest
|
||||
// sample rather than degenerating to "no samples".
|
||||
let rank = ((q * self.count as f64).ceil() as u64).max(1);
|
||||
let mut cumulative = 0u64;
|
||||
for (index, &n) in self.buckets.iter().enumerate() {
|
||||
cumulative += n;
|
||||
if cumulative >= rank {
|
||||
return Some(BUCKET_LABELS[index]);
|
||||
}
|
||||
}
|
||||
// Unreachable while `count` is the sum of the buckets, but returning the
|
||||
// top bucket is the fail-loud answer rather than a panic in a metric.
|
||||
Some(BUCKET_LABELS[BUCKET_LABELS.len() - 1])
|
||||
}
|
||||
|
||||
/// Non-empty buckets as `(label, count)`, ascending. Empty buckets are
|
||||
/// dropped so a summary line stays readable.
|
||||
pub fn distribution(&self) -> Vec<(&'static str, u64)> {
|
||||
self.buckets
|
||||
.iter()
|
||||
.enumerate()
|
||||
.filter(|&(_, &n)| n > 0)
|
||||
.map(|(index, &n)| (BUCKET_LABELS[index], n))
|
||||
.collect()
|
||||
}
|
||||
}
|
||||
|
||||
/// One handled event, as timed by the I/O edge.
|
||||
///
|
||||
/// Ticks are the AEC validator's clock, not graph changes, so [`Metrics`] counts
|
||||
/// them separately — folding them into the event rate would inflate it by a
|
||||
/// constant 4 Hz and hide the real graph churn.
|
||||
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
|
||||
pub struct Sample {
|
||||
/// Monotonic microseconds (since observer start) at which handling began.
|
||||
pub at_us: u64,
|
||||
/// Microseconds between the previous sample's completion and `at_us`. Zero
|
||||
/// for the first sample.
|
||||
pub gap_us: u64,
|
||||
/// Time spent in the AEC observe + taint recompute.
|
||||
pub recompute_us: u64,
|
||||
/// Time spent serialising and writing the record, zero when nothing was
|
||||
/// emitted. Separate from `recompute_us` because O5 asks about queueing
|
||||
/// behind recompute **or logging** — and if logging turns out to dominate,
|
||||
/// that is a fixable problem of a different kind.
|
||||
pub emit_us: u64,
|
||||
pub kind: EventKind,
|
||||
}
|
||||
|
||||
/// Rolling O5 state. Fold samples in with [`Metrics::record`]; read with
|
||||
/// [`Metrics::summary`].
|
||||
#[derive(Clone, Debug, Default)]
|
||||
pub struct Metrics {
|
||||
graph_events: u64,
|
||||
tick_events: u64,
|
||||
emitted_records: u64,
|
||||
recompute: Histogram,
|
||||
emit: Histogram,
|
||||
busy_us: u64,
|
||||
queued_events: u64,
|
||||
first_event_us: Option<u64>,
|
||||
last_completion_us: u64,
|
||||
}
|
||||
|
||||
impl Metrics {
|
||||
pub fn record(&mut self, sample: Sample) {
|
||||
match sample.kind {
|
||||
EventKind::Graph => self.graph_events += 1,
|
||||
EventKind::Tick => self.tick_events += 1,
|
||||
}
|
||||
self.recompute.record(sample.recompute_us);
|
||||
if sample.emit_us > 0 {
|
||||
self.emitted_records += 1;
|
||||
self.emit.record(sample.emit_us);
|
||||
}
|
||||
self.busy_us = self
|
||||
.busy_us
|
||||
.saturating_add(sample.recompute_us)
|
||||
.saturating_add(sample.emit_us);
|
||||
|
||||
// The first sample has no predecessor to have queued behind.
|
||||
if self.first_event_us.is_some() && sample.gap_us <= QUEUE_THRESHOLD_US {
|
||||
self.queued_events += 1;
|
||||
}
|
||||
self.first_event_us.get_or_insert(sample.at_us);
|
||||
self.last_completion_us = sample
|
||||
.at_us
|
||||
.saturating_add(sample.recompute_us)
|
||||
.saturating_add(sample.emit_us);
|
||||
}
|
||||
|
||||
pub fn summary(&self) -> Summary {
|
||||
let span_us = self
|
||||
.first_event_us
|
||||
.map(|first| self.last_completion_us.saturating_sub(first))
|
||||
.unwrap_or(0);
|
||||
// A rate needs a span to divide by; one event in zero elapsed time has
|
||||
// no rate, and reporting a made-up one is worse than reporting none.
|
||||
let graph_events_per_sec = (span_us > 0)
|
||||
.then(|| self.graph_events as f64 * 1_000_000.0 / span_us as f64)
|
||||
.map(round_2);
|
||||
let busy_fraction = (span_us > 0).then(|| round_4(self.busy_us as f64 / span_us as f64));
|
||||
|
||||
Summary {
|
||||
graph_events: self.graph_events,
|
||||
tick_events: self.tick_events,
|
||||
emitted_records: self.emitted_records,
|
||||
span_us,
|
||||
graph_events_per_sec,
|
||||
recompute_max_us: self.recompute.max_us(),
|
||||
recompute_mean_us: self.recompute.mean_us(),
|
||||
recompute_p50: self.recompute.quantile_bucket(0.50),
|
||||
recompute_p90: self.recompute.quantile_bucket(0.90),
|
||||
recompute_p99: self.recompute.quantile_bucket(0.99),
|
||||
recompute_distribution: self.recompute.distribution(),
|
||||
emit_max_us: self.emit.max_us(),
|
||||
emit_mean_us: self.emit.mean_us(),
|
||||
emit_distribution: self.emit.distribution(),
|
||||
busy_us: self.busy_us,
|
||||
busy_fraction,
|
||||
queued_events: self.queued_events,
|
||||
queue_threshold_us: QUEUE_THRESHOLD_US,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// The O5 answer, as emitted.
|
||||
#[derive(Clone, Debug, PartialEq, Serialize)]
|
||||
pub struct Summary {
|
||||
pub graph_events: u64,
|
||||
pub tick_events: u64,
|
||||
pub emitted_records: u64,
|
||||
/// First event to last completion, microseconds.
|
||||
pub span_us: u64,
|
||||
pub graph_events_per_sec: Option<f64>,
|
||||
pub recompute_max_us: u64,
|
||||
pub recompute_mean_us: Option<u64>,
|
||||
pub recompute_p50: Option<&'static str>,
|
||||
pub recompute_p90: Option<&'static str>,
|
||||
pub recompute_p99: Option<&'static str>,
|
||||
pub recompute_distribution: Vec<(&'static str, u64)>,
|
||||
pub emit_max_us: u64,
|
||||
pub emit_mean_us: Option<u64>,
|
||||
pub emit_distribution: Vec<(&'static str, u64)>,
|
||||
/// Total observer-thread time spent recomputing and logging.
|
||||
pub busy_us: u64,
|
||||
/// `busy_us / span_us` — the share of wall time the observer thread could
|
||||
/// not be servicing PipeWire. Needs no inference, unlike `queued_events`.
|
||||
pub busy_fraction: Option<f64>,
|
||||
/// Events that began within `queue_threshold_us` of the previous sample's
|
||||
/// completion — a **lower bound** on backlog, see the module header.
|
||||
pub queued_events: u64,
|
||||
pub queue_threshold_us: u64,
|
||||
}
|
||||
|
||||
/// Keep the JSON readable: a rate to two decimals and a fraction to four are
|
||||
/// well past the precision any of this is good to.
|
||||
fn round_2(value: f64) -> f64 {
|
||||
(value * 100.0).round() / 100.0
|
||||
}
|
||||
|
||||
fn round_4(value: f64) -> f64 {
|
||||
(value * 10_000.0).round() / 10_000.0
|
||||
}
|
||||
@@ -0,0 +1,487 @@
|
||||
//! Phase 5 — dry-run audit mode 🚦 (impl plan §5).
|
||||
//!
|
||||
//! **This phase adds no capability. Its entire purpose is to be wrong loudly
|
||||
//! and safely.** It runs phases 2–4 against the *live* graph on every graph
|
||||
//! event and reports what they conclude. It creates no links, loads no modules,
|
||||
//! and changes no routing — the only thing it produces is a line of JSON.
|
||||
//!
|
||||
//! Why this is the gate the plan marks 🚦: the defects that matter here are
|
||||
//! graph-*reasoning* defects. The 57 phase-2 fixture tests prove the engine
|
||||
//! matches my model of PipeWire; only a live run proves my model matches
|
||||
//! PipeWire. A wrong answer at this phase costs a log line. The same wrong
|
||||
//! answer in phase 6 costs an echo — the sharer's own voice, copied back into
|
||||
//! the share, which is the failure this whole design exists to prevent.
|
||||
//!
|
||||
//! ## The one structural requirement (§5.1)
|
||||
//!
|
||||
//! Every emitted record carries the **complete candidate universe partitioned
|
||||
//! into exact eligible and excluded sets**, with a stable reason code on each
|
||||
//! excluded row — never a spot check on named nodes. Checking only the nodes a
|
||||
//! row names constrains nothing about the rest, and it lets the degenerate
|
||||
//! "exclude everything" implementation pass: that build is silent, produces no
|
||||
//! echo, and satisfies any assertion phrased purely as *this must be excluded*.
|
||||
//! Asserting the eligible half of each row is what fails it. That requirement is
|
||||
//! also the plan's answer to open question O7 (over-exclusion needs no separate
|
||||
//! gate — it is subsumed by this one).
|
||||
//!
|
||||
//! ## What is deliberately *not* here
|
||||
//!
|
||||
//! - **No link creation, and no code path that could reach one.** The auditor
|
||||
//! consumes a [`Projection`] and returns a record. It has no handle to
|
||||
//! anything mutable.
|
||||
//! - **No stdout.** Records go to stderr as JSON Lines
|
||||
//! ([`sink`]) because peerspeak parses pixelpass's stdout event stream
|
||||
//! (`screenshare/mod.rs:92`); a stray line there corrupts it.
|
||||
//! - **No `--aec` CLI flag.** That surface is phase 7's mode selector. The audit
|
||||
//! takes its AEC identity from `PIXELPASS_AUDIO_AUDIT_AEC` through the
|
||||
//! *same* [`parse_aec_arg`] the real flag will use, so the parser and the
|
||||
//! validator are both exercised without committing to a public interface
|
||||
//! before it is designed.
|
||||
//!
|
||||
//! ## Fan-out gating vs. taint (read before interpreting a record)
|
||||
//!
|
||||
//! Two independent things can exclude a candidate and the record keeps them
|
||||
//! distinguishable:
|
||||
//!
|
||||
//! - The **taint engine** (phase 2) excludes individual nodes with its own
|
||||
//! reason codes — `peerspeak-owned`, `aec-identity`, `tainted-upstream`, …
|
||||
//! - The **AEC validator** (phase 4) can forbid fan-out *entirely*, regardless
|
||||
//! of taint, whenever the configured identity is unvalidated, failed or
|
||||
//! revoked. Silence over echo.
|
||||
//!
|
||||
//! When the gate is shut, a candidate the engine would have called eligible is
|
||||
//! reported excluded with an audit-level reason ([`GateReason`]); a candidate
|
||||
//! the engine excluded on its own keeps *its* reason, because that names the
|
||||
//! mechanism that actually applies to it. `fan_out_permitted` on the record
|
||||
//! carries the gate state, so the two cases are always tellable apart.
|
||||
//!
|
||||
//! **Consequence for the §5.1 matrix:** every row whose point is the
|
||||
//! eligible/excluded partition must run with `PIXELPASS_AUDIO_AUDIT_AEC=off`
|
||||
//! (state `NotConfigured`, gate open). Row 12 — the AEC lifecycle row — is the
|
||||
//! one that runs with a real `pulse-module:<idx>`, and the gate slamming shut is
|
||||
//! precisely what it asserts.
|
||||
|
||||
#![allow(dead_code)] // Trigger paths are wired by `sink` + `run`; rows are read by tests.
|
||||
|
||||
pub mod metrics;
|
||||
pub mod run;
|
||||
pub mod sink;
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests;
|
||||
|
||||
use serde::Serialize;
|
||||
|
||||
use crate::host::aec::{AecConfig, AecState, AecValidator};
|
||||
use crate::host::observer::{EventKind, Millis, Projection, Readiness};
|
||||
use crate::host::taint::snapshot::Serial;
|
||||
use crate::host::taint::{Decisions, Eligibility, ExclusionCtx, StickyState, evaluate};
|
||||
|
||||
/// How long the AEC validator may sit in `Validating` after the graph first
|
||||
/// reports ready before failing closed. Generous relative to the observer's own
|
||||
/// 2 s readiness budget: in the audit a `Failed` is a diagnostic, and timing out
|
||||
/// early would report an absent module that was merely slow to appear.
|
||||
pub const AEC_VALIDATION_TIMEOUT_MILLIS: Millis = 5_000;
|
||||
|
||||
/// Everything the auditor needs beyond the live graph.
|
||||
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
|
||||
pub struct AuditConfig {
|
||||
/// The AEC identity to validate, as parsed from
|
||||
/// `PIXELPASS_AUDIO_AUDIT_AEC`. Defaults to [`AecConfig::Off`] — an audit
|
||||
/// run is not a share, so "there is no echo canceller in play" is the
|
||||
/// honest default, and it is what leaves the fan-out gate open for the
|
||||
/// partition rows.
|
||||
pub aec: AecConfig,
|
||||
pub aec_timeout: Millis,
|
||||
}
|
||||
|
||||
impl Default for AuditConfig {
|
||||
fn default() -> Self {
|
||||
Self {
|
||||
aec: AecConfig::Off,
|
||||
aec_timeout: AEC_VALIDATION_TIMEOUT_MILLIS,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// An audit-level exclusion: the AEC validator has shut the fan-out gate. These
|
||||
/// codes are disjoint from the taint engine's
|
||||
/// [`Reason::code`](crate::host::taint::Reason::code) values, so a reader never
|
||||
/// has to know which layer produced a code to interpret it.
|
||||
// The shared `Aec` prefix is the point: `GateReason::Validating` and
|
||||
// `AecState::Validating` would be one careless glob import away from being
|
||||
// confused, and these three are the *audit's* view of that machine, not the
|
||||
// machine itself.
|
||||
#[allow(clippy::enum_variant_names)]
|
||||
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
|
||||
pub enum GateReason {
|
||||
/// The configured AEC identity has not been seen yet. Not an error — the
|
||||
/// module may still be loading — but no fan-out happens meanwhile.
|
||||
AecValidating,
|
||||
/// The deadline passed with the identity never observed.
|
||||
AecFailed,
|
||||
/// The whole identity disappeared mid-run: every node bearing the index is
|
||||
/// gone (v3.4 §5.3).
|
||||
AecRevoked,
|
||||
}
|
||||
|
||||
impl GateReason {
|
||||
pub fn code(self) -> &'static str {
|
||||
match self {
|
||||
Self::AecValidating => "aec-validating",
|
||||
Self::AecFailed => "aec-failed",
|
||||
Self::AecRevoked => "aec-revoked",
|
||||
}
|
||||
}
|
||||
|
||||
/// The gate reason implied by a validator state, or `None` when fan-out is
|
||||
/// permitted. Mirrors [`AecValidator::fan_out_permitted`] — kept as one
|
||||
/// `match` over the same enum so the two cannot drift: every state that
|
||||
/// permits fan-out maps to `None` and every state that forbids it maps to a
|
||||
/// code.
|
||||
pub fn from_state(state: AecState) -> Option<Self> {
|
||||
match state {
|
||||
AecState::NotConfigured | AecState::Validated => None,
|
||||
AecState::Validating => Some(Self::AecValidating),
|
||||
AecState::Failed => Some(Self::AecFailed),
|
||||
AecState::Revoked => Some(Self::AecRevoked),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Stable string for an [`AecState`], for the record's `aec_state` field.
|
||||
///
|
||||
/// Defined here rather than on [`AecState`] to keep the merged phase-4 module
|
||||
/// untouched by a reporting concern.
|
||||
fn aec_state_code(state: AecState) -> &'static str {
|
||||
match state {
|
||||
AecState::NotConfigured => "not-configured",
|
||||
AecState::Validating => "validating",
|
||||
AecState::Validated => "validated",
|
||||
AecState::Failed => "failed",
|
||||
AecState::Revoked => "revoked",
|
||||
}
|
||||
}
|
||||
|
||||
/// Stable string for the observer's readiness epoch.
|
||||
fn readiness_code(readiness: Readiness) -> &'static str {
|
||||
match readiness {
|
||||
Readiness::Waiting => "waiting",
|
||||
Readiness::Complete => "complete",
|
||||
Readiness::TimedOut => "timed-out",
|
||||
}
|
||||
}
|
||||
|
||||
/// One candidate node's effective answer. `reason` is `None` exactly when
|
||||
/// `eligible` is true.
|
||||
#[derive(Clone, Debug, PartialEq, Eq, Serialize)]
|
||||
pub struct AuditRow {
|
||||
pub serial: u64,
|
||||
pub name: Option<String>,
|
||||
pub eligible: bool,
|
||||
#[serde(skip_serializing_if = "Option::is_none")]
|
||||
pub reason: Option<&'static str>,
|
||||
/// The exclusion was carried over from a previous snapshot rather than
|
||||
/// derived from the current topology (phase-2 stickiness).
|
||||
pub sticky: bool,
|
||||
}
|
||||
|
||||
/// A tainted node of *any* media role, not just fan-out candidates. Candidates
|
||||
/// already appear in [`AuditBody::candidates`]; this is the diagnostic view —
|
||||
/// when a candidate's exclusion is a surprise, the taint that reached it is the
|
||||
/// next question, and it usually sits on a node that is not itself a candidate.
|
||||
#[derive(Clone, Debug, PartialEq, Eq, Serialize)]
|
||||
pub struct TaintRow {
|
||||
pub serial: u64,
|
||||
pub name: Option<String>,
|
||||
pub reason: &'static str,
|
||||
pub sticky: bool,
|
||||
}
|
||||
|
||||
/// A node carrying a peerspeak ownership carrier on a role the engine does not
|
||||
/// honour it on (round 10, R10-1). `role` is the point of the row: it says
|
||||
/// which non-producer role the tag turned up on, which is what distinguishes a
|
||||
/// producer-side bug from an impersonation attempt.
|
||||
#[derive(Clone, Debug, PartialEq, Eq, Serialize)]
|
||||
pub struct IgnoredTagRow {
|
||||
pub serial: u64,
|
||||
pub name: Option<String>,
|
||||
pub role: &'static str,
|
||||
}
|
||||
|
||||
/// The decision content of one recompute — everything except which recompute it
|
||||
/// was. Split out from [`AuditRecord`] so "did anything actually change?" is a
|
||||
/// derived `==` rather than a hand-maintained field comparison that a later
|
||||
/// field addition could silently fall out of.
|
||||
#[derive(Clone, Debug, PartialEq, Eq, Serialize)]
|
||||
pub struct AuditBody {
|
||||
/// The observer's dynamic readiness. False ⇒ every candidate is excluded
|
||||
/// `graph-not-ready`; no decision from a partial graph is a decision.
|
||||
pub graph_ready: bool,
|
||||
/// The sticky readiness epoch, which distinguishes the three ways
|
||||
/// `graph_ready` can be false (see [`Projection::readiness`]).
|
||||
pub epoch: &'static str,
|
||||
pub aec_state: &'static str,
|
||||
/// The index handed to the taint engine — `Some` only while `Validated`.
|
||||
#[serde(skip_serializing_if = "Option::is_none")]
|
||||
pub aec_module_id: Option<u64>,
|
||||
/// Whether the AEC validator permits fan-out at all right now.
|
||||
pub fan_out_permitted: bool,
|
||||
/// The audit-level reason fan-out is forbidden, when it is.
|
||||
#[serde(skip_serializing_if = "Option::is_none")]
|
||||
pub gate_reason: Option<&'static str>,
|
||||
/// **The complete candidate universe**, ascending by serial — every
|
||||
/// `Stream/Output/Audio` node in the snapshot, partitioned. §5.1's exact
|
||||
/// partition is `candidates`, not a subset of it.
|
||||
pub candidates: Vec<AuditRow>,
|
||||
pub eligible_count: usize,
|
||||
pub excluded_count: usize,
|
||||
/// Taint across all node roles, ascending by serial.
|
||||
pub taint: Vec<TaintRow>,
|
||||
/// Nodes carrying a peerspeak ownership carrier that the engine
|
||||
/// **ignored** because they are not `Stream/Output/Audio` (round 10,
|
||||
/// R10-1). Normally empty; a non-empty list means either peerspeak is
|
||||
/// tagging something it should not, or a process is impersonating the
|
||||
/// tag. Neither is an exclusion, and neither should be silent.
|
||||
///
|
||||
/// Omitted from the JSONL when empty, so it costs nothing on the common
|
||||
/// path and is impossible to miss when it is not.
|
||||
#[serde(skip_serializing_if = "Vec::is_empty")]
|
||||
pub ignored_ownership_tags: Vec<IgnoredTagRow>,
|
||||
}
|
||||
|
||||
impl AuditBody {
|
||||
/// Serials of eligible candidates, ascending — the half of the partition an
|
||||
/// exclude-everything build fails.
|
||||
pub fn eligible(&self) -> Vec<u64> {
|
||||
self.candidates
|
||||
.iter()
|
||||
.filter(|row| row.eligible)
|
||||
.map(|row| row.serial)
|
||||
.collect()
|
||||
}
|
||||
|
||||
/// `(serial, reason code)` for excluded candidates, ascending.
|
||||
pub fn excluded(&self) -> Vec<(u64, &'static str)> {
|
||||
self.candidates
|
||||
.iter()
|
||||
.filter(|row| !row.eligible)
|
||||
.map(|row| (row.serial, row.reason.unwrap_or("?")))
|
||||
.collect()
|
||||
}
|
||||
|
||||
/// The eligible candidate with this name, if any. Convenience for the
|
||||
/// matrix rows, which name nodes rather than serials.
|
||||
pub fn row_named(&self, name: &str) -> Option<&AuditRow> {
|
||||
self.candidates
|
||||
.iter()
|
||||
.find(|row| row.name.as_deref() == Some(name))
|
||||
}
|
||||
}
|
||||
|
||||
/// One recompute, as emitted.
|
||||
#[derive(Clone, Debug, PartialEq, Eq, Serialize)]
|
||||
pub struct AuditRecord {
|
||||
/// Monotonic per-run counter over *every* recompute, emitted or suppressed,
|
||||
/// so a gap in the emitted sequence is visibly a suppression rather than a
|
||||
/// lost line.
|
||||
pub seq: u64,
|
||||
pub trigger: &'static str,
|
||||
/// Observer-clock milliseconds at which this recompute ran.
|
||||
pub at_ms: Millis,
|
||||
#[serde(flatten)]
|
||||
pub body: AuditBody,
|
||||
}
|
||||
|
||||
/// What one [`Auditor::observe`] produced.
|
||||
#[derive(Clone, Debug, PartialEq, Eq)]
|
||||
pub struct AuditOutcome {
|
||||
pub record: AuditRecord,
|
||||
/// Whether the record should be written. See [`Auditor::observe`].
|
||||
pub emit: bool,
|
||||
}
|
||||
|
||||
/// The dry-run auditor: phases 2–4 folded together over a live projection.
|
||||
///
|
||||
/// Read-only by construction — it borrows a [`Projection`] and owns only the
|
||||
/// state phases 2 and 4 thread explicitly ([`StickyState`], [`AecValidator`]).
|
||||
/// There is no field here through which a link could be created.
|
||||
#[derive(Clone, Debug)]
|
||||
pub struct Auditor {
|
||||
validator: AecValidator,
|
||||
sticky: StickyState,
|
||||
seq: u64,
|
||||
/// The body of the last record actually written, for change suppression.
|
||||
last_emitted: Option<AuditBody>,
|
||||
}
|
||||
|
||||
impl Auditor {
|
||||
pub fn new(config: AuditConfig) -> Self {
|
||||
Self {
|
||||
validator: AecValidator::new(config.aec, config.aec_timeout),
|
||||
sticky: StickyState::default(),
|
||||
seq: 0,
|
||||
last_emitted: None,
|
||||
}
|
||||
}
|
||||
|
||||
pub fn aec_state(&self) -> AecState {
|
||||
self.validator.state()
|
||||
}
|
||||
|
||||
pub fn sticky(&self) -> &StickyState {
|
||||
&self.sticky
|
||||
}
|
||||
|
||||
/// Fold one projection into the audit.
|
||||
///
|
||||
/// **Called once per applied registry event — never on a coalesced batch.**
|
||||
/// That is not a performance preference, it is the phase-4 integration
|
||||
/// contract (`aec/mod.rs`, the `Validated` arm): revocation is detected by
|
||||
/// observing the *empty gap* between a module unload and the next reload,
|
||||
/// and module indices are reused verbatim (v3.4 §5.2 correction 3). Coalesce
|
||||
/// across that gap and a fresh module silently inherits a dead module's
|
||||
/// validated identity. [`sink`] is what upholds this, by running the
|
||||
/// recompute inline on the observer thread rather than polling
|
||||
/// [`RegistryObserverHandle::latest`](crate::host::observer::adapter::RegistryObserverHandle::latest),
|
||||
/// which coalesces by nature.
|
||||
///
|
||||
/// `emit` is true for every graph-triggered recompute, and for a
|
||||
/// tick-triggered one only when the decision content changed. Ticks arrive
|
||||
/// at a constant 4 Hz purely to drive the AEC deadline; emitting an
|
||||
/// identical record four times a second would bury the graph events the
|
||||
/// audit exists to show. `seq` still advances on suppressed records, so
|
||||
/// nothing about the run is silently unaccounted for.
|
||||
pub fn observe(
|
||||
&mut self,
|
||||
projection: &Projection,
|
||||
kind: EventKind,
|
||||
now: Millis,
|
||||
) -> AuditOutcome {
|
||||
self.seq += 1;
|
||||
|
||||
// Phase 4 first: its verdict is an *input* to phase 2 via
|
||||
// `ExclusionCtx::aec_module_id`, so observing the graph in the other
|
||||
// order would evaluate taint against the previous recompute's identity.
|
||||
self.validator
|
||||
.observe(&projection.snapshot, projection.graph_ready, now);
|
||||
let aec_state = self.validator.state();
|
||||
let gate_reason = GateReason::from_state(aec_state);
|
||||
|
||||
let ctx = ExclusionCtx {
|
||||
aec_module_id: self.validator.validated_module_id(),
|
||||
pipewire_pulse_pid: projection.pipewire_pulse_pid,
|
||||
// The audit creates nothing, so it owns nothing. Another host's
|
||||
// capture sink is still caught — by the `pixelpass_capture_*` name
|
||||
// prefix (v3.4 §6.2), which is what §5.1 row 7 exercises — so an
|
||||
// empty set costs the matrix nothing.
|
||||
pixelpass_owned: Default::default(),
|
||||
graph_ready: projection.graph_ready,
|
||||
};
|
||||
|
||||
let (decisions, sticky) = evaluate(&projection.snapshot, &ctx, &self.sticky);
|
||||
self.sticky = sticky;
|
||||
|
||||
let body = build_body(
|
||||
projection,
|
||||
&decisions,
|
||||
aec_state,
|
||||
self.validator.validated_module_id(),
|
||||
gate_reason,
|
||||
);
|
||||
|
||||
let emit = kind == EventKind::Graph || self.last_emitted.as_ref() != Some(&body);
|
||||
if emit {
|
||||
self.last_emitted = Some(body.clone());
|
||||
}
|
||||
|
||||
AuditOutcome {
|
||||
record: AuditRecord {
|
||||
seq: self.seq,
|
||||
trigger: kind.code(),
|
||||
at_ms: now,
|
||||
body,
|
||||
},
|
||||
emit,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn build_body(
|
||||
projection: &Projection,
|
||||
decisions: &Decisions,
|
||||
aec_state: AecState,
|
||||
aec_module_id: Option<u64>,
|
||||
gate_reason: Option<GateReason>,
|
||||
) -> AuditBody {
|
||||
let candidates: Vec<AuditRow> = decisions
|
||||
.candidates
|
||||
.values()
|
||||
.map(|decision| {
|
||||
// The engine's own reason wins when it has one: it names the
|
||||
// mechanism that actually excluded *this* node, which is what the
|
||||
// §5.1 rows assert. The gate reason applies only to candidates the
|
||||
// engine would have passed — otherwise a shut gate would erase every
|
||||
// reason code in the record and the matrix would stop constraining
|
||||
// the engine at all.
|
||||
let (eligible, reason, sticky) = match decision.eligibility {
|
||||
Eligibility::NotEligible { reason, sticky } => (false, Some(reason.code()), sticky),
|
||||
Eligibility::Eligible => match gate_reason {
|
||||
Some(gate) => (false, Some(gate.code()), false),
|
||||
None => (true, None, false),
|
||||
},
|
||||
};
|
||||
AuditRow {
|
||||
serial: decision.serial.0,
|
||||
name: decision.name.clone(),
|
||||
eligible,
|
||||
reason,
|
||||
sticky,
|
||||
}
|
||||
})
|
||||
.collect();
|
||||
|
||||
let eligible_count = candidates.iter().filter(|row| row.eligible).count();
|
||||
|
||||
let taint: Vec<TaintRow> = decisions
|
||||
.taint
|
||||
.iter()
|
||||
.map(|(&serial, entry)| TaintRow {
|
||||
serial: serial.0,
|
||||
name: node_name(projection, serial),
|
||||
reason: entry.reason.code(),
|
||||
sticky: entry.sticky,
|
||||
})
|
||||
.collect();
|
||||
|
||||
let ignored_ownership_tags: Vec<IgnoredTagRow> =
|
||||
crate::host::taint::misplaced_ownership_tags(&projection.snapshot)
|
||||
.into_iter()
|
||||
.map(|node| IgnoredTagRow {
|
||||
serial: node.serial.0,
|
||||
name: node.name.clone(),
|
||||
role: node.role.code(),
|
||||
})
|
||||
.collect();
|
||||
|
||||
AuditBody {
|
||||
graph_ready: projection.graph_ready,
|
||||
epoch: readiness_code(projection.readiness),
|
||||
aec_state: aec_state_code(aec_state),
|
||||
aec_module_id,
|
||||
fan_out_permitted: gate_reason.is_none(),
|
||||
gate_reason: gate_reason.map(GateReason::code),
|
||||
excluded_count: candidates.len() - eligible_count,
|
||||
eligible_count,
|
||||
candidates,
|
||||
taint,
|
||||
ignored_ownership_tags,
|
||||
}
|
||||
}
|
||||
|
||||
fn node_name(projection: &Projection, serial: Serial) -> Option<String> {
|
||||
projection
|
||||
.snapshot
|
||||
.node(serial)
|
||||
.and_then(|node| node.name.clone())
|
||||
}
|
||||
@@ -0,0 +1,170 @@
|
||||
//! Triggering the dry-run audit: environment parsing and the two entry points.
|
||||
//!
|
||||
//! The impl plan §5 specifies a **hidden trigger**, `PIXELPASS_AUDIO_AUDIT=1`.
|
||||
//! It is honoured in two places, which answer two different questions:
|
||||
//!
|
||||
//! - **Inside a real `pixelpass host` run** ([`spawn_if_enabled`]) — proves the
|
||||
//! audit works in the code path phase 6 will actually mutate. This is the
|
||||
//! plan-literal reading of the trigger.
|
||||
//! - **Standalone** ([`run_standalone`], behind the hidden `--audit-audio`
|
||||
//! flag) — observer plus auditor and nothing else: no iroh endpoint, no
|
||||
//! display-server detection, no capture pipeline, no ticket. This is what
|
||||
//! drives the §5.1 matrix, because a row that fails should fail for a reason
|
||||
//! about *audio*, not because a relay was unreachable.
|
||||
//!
|
||||
//! Both paths run the same [`AuditSink`] over the same observer, so neither is a
|
||||
//! simulation of the other.
|
||||
|
||||
use std::fs::OpenOptions;
|
||||
use std::io::Write;
|
||||
|
||||
use anyhow::{Context, Result, bail};
|
||||
|
||||
use super::sink::AuditSink;
|
||||
use super::{AEC_VALIDATION_TIMEOUT_MILLIS, AuditConfig};
|
||||
use crate::common::signal;
|
||||
use crate::host::aec::{AecConfig, AecParseError, parse_aec_arg};
|
||||
use crate::host::observer::adapter::RegistryObserverHandle;
|
||||
|
||||
/// The hidden trigger (impl plan §5). Exactly `1` enables the audit; anything
|
||||
/// else, including `true` or `yes`, does not.
|
||||
///
|
||||
/// Deliberately strict. This variable can only arrive by someone typing it, and
|
||||
/// a value that *looks* enabling but is not would produce a silent no-op — the
|
||||
/// single most annoying failure mode for a diagnostic tool. A mistyped value
|
||||
/// gets a warning (see [`enabled`]) rather than silence.
|
||||
pub const AUDIT_ENV: &str = "PIXELPASS_AUDIO_AUDIT";
|
||||
|
||||
/// The AEC identity for the audit, in the `--aec` grammar (`off` or
|
||||
/// `pulse-module:<idx>`). Absent ⇒ `off`.
|
||||
pub const AUDIT_AEC_ENV: &str = "PIXELPASS_AUDIO_AUDIT_AEC";
|
||||
|
||||
/// Redirect the JSON Lines stream to this file instead of stderr.
|
||||
pub const AUDIT_FILE_ENV: &str = "PIXELPASS_AUDIO_AUDIT_FILE";
|
||||
|
||||
/// Whether the hidden trigger is set.
|
||||
pub fn enabled() -> bool {
|
||||
match std::env::var(AUDIT_ENV) {
|
||||
Ok(value) if value == "1" => true,
|
||||
Ok(value) => {
|
||||
tracing::warn!(
|
||||
"{AUDIT_ENV}={value:?} is not `1`; the audio audit stays off. \
|
||||
Set {AUDIT_ENV}=1 to enable it."
|
||||
);
|
||||
false
|
||||
}
|
||||
Err(_) => false,
|
||||
}
|
||||
}
|
||||
|
||||
/// Build the audit configuration from the environment.
|
||||
///
|
||||
/// A malformed `PIXELPASS_AUDIO_AUDIT_AEC` is **fatal**, matching the phase-4
|
||||
/// rule that a bad `--aec` value must not silently become "no AEC": there is no
|
||||
/// fail-closed default index, so a wrong or dropped one would exclude the wrong
|
||||
/// node (or nothing at all) and the audit would confidently report a partition
|
||||
/// computed against an identity nobody asked for.
|
||||
pub fn config_from_env() -> Result<AuditConfig> {
|
||||
let aec = match std::env::var(AUDIT_AEC_ENV) {
|
||||
Ok(raw) => parse_aec_arg(&raw).map_err(|e| {
|
||||
anyhow::anyhow!(
|
||||
"{AUDIT_AEC_ENV}={raw:?} is not a valid AEC argument ({}). \
|
||||
Expected `off` or `pulse-module:<index>`, where the index is a bare decimal.",
|
||||
describe(e)
|
||||
)
|
||||
})?,
|
||||
Err(std::env::VarError::NotPresent) => AecConfig::Off,
|
||||
Err(e) => bail!("{AUDIT_AEC_ENV} is not readable: {e}"),
|
||||
};
|
||||
Ok(AuditConfig {
|
||||
aec,
|
||||
aec_timeout: AEC_VALIDATION_TIMEOUT_MILLIS,
|
||||
})
|
||||
}
|
||||
|
||||
fn describe(error: AecParseError) -> &'static str {
|
||||
match error {
|
||||
AecParseError::Empty => "the value was empty",
|
||||
AecParseError::UnknownForm => "not `off` and not `pulse-module:...`",
|
||||
AecParseError::MissingIndex => "`pulse-module:` with no index after the colon",
|
||||
AecParseError::InvalidIndex => {
|
||||
"the index was not a bare decimal (no sign, whitespace, or non-digits) that fits in u64"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Where the JSON Lines go. Stderr unless `PIXELPASS_AUDIO_AUDIT_FILE` names a
|
||||
/// file, which is appended to rather than truncated — a matrix run that restarts
|
||||
/// the process mid-scenario should not lose the rows it already recorded.
|
||||
fn writer_from_env() -> Result<Box<dyn Write + Send>> {
|
||||
match std::env::var(AUDIT_FILE_ENV) {
|
||||
Ok(path) if !path.is_empty() => {
|
||||
let file = OpenOptions::new()
|
||||
.create(true)
|
||||
.append(true)
|
||||
.open(&path)
|
||||
.with_context(|| format!("{AUDIT_FILE_ENV}={path:?} could not be opened"))?;
|
||||
tracing::info!("audio audit: writing records to {path}");
|
||||
Ok(Box::new(file))
|
||||
}
|
||||
_ => Ok(Box::new(std::io::stderr())),
|
||||
}
|
||||
}
|
||||
|
||||
/// Construct the sink and spawn the observer behind it.
|
||||
fn spawn_audit() -> Result<RegistryObserverHandle> {
|
||||
let config = config_from_env()?;
|
||||
let sink = AuditSink::new(config, writer_from_env()?);
|
||||
tracing::info!(
|
||||
aec = ?config.aec,
|
||||
"audio audit: dry run active — decisions are logged, no links are created"
|
||||
);
|
||||
RegistryObserverHandle::spawn_with_sink(Some(Box::new(sink)))
|
||||
}
|
||||
|
||||
/// Start the audit if the hidden trigger is set, for a `pixelpass host` run.
|
||||
///
|
||||
/// The returned handle must be held for the lifetime of the run: dropping it
|
||||
/// stops the observer thread and flushes the final O5 summary.
|
||||
///
|
||||
/// Returns `Err` only when the trigger *was* set and starting failed — a
|
||||
/// misconfigured audit is worth failing the run over, because the alternative is
|
||||
/// a host that silently is not being audited while its operator believes it is.
|
||||
pub fn spawn_if_enabled() -> Result<Option<RegistryObserverHandle>> {
|
||||
if !enabled() {
|
||||
return Ok(None);
|
||||
}
|
||||
spawn_audit().map(Some)
|
||||
}
|
||||
|
||||
/// The standalone audit: run the observer and the auditor, and nothing else,
|
||||
/// until ctrl-c.
|
||||
///
|
||||
/// Does not consult [`AUDIT_ENV`] — reaching this function required passing the
|
||||
/// hidden `--audit-audio` flag, which is already an explicit request. The
|
||||
/// environment still supplies the AEC identity and the output file.
|
||||
pub async fn run_standalone() -> Result<()> {
|
||||
let cancel = signal::install_ctrl_c();
|
||||
let handle = spawn_audit()?;
|
||||
|
||||
eprintln!(
|
||||
"pixelpass audio audit (dry run): observing the live PipeWire graph.\n\
|
||||
No links are created and no routing changes. Ctrl-C to stop."
|
||||
);
|
||||
|
||||
// SIGTERM as well as ctrl-c, because this mode is driven by scripts as much
|
||||
// as by hand — `timeout`, a matrix harness, and systemd all send SIGTERM,
|
||||
// and the default disposition would kill the process before the sink's
|
||||
// `Drop` writes the final O5 summary. Losing that summary is losing the
|
||||
// whole §5.2 measurement for that run.
|
||||
let mut sigterm = signal::terminate_stream()?;
|
||||
tokio::select! {
|
||||
_ = cancel.cancelled() => {}
|
||||
_ = sigterm.recv() => tracing::info!("SIGTERM received, shutting down"),
|
||||
}
|
||||
// Explicit rather than incidental: this drop stops the PipeWire thread,
|
||||
// which drops the sink, which writes the final metrics line. Letting it fall
|
||||
// out of scope would do the same thing, but the ordering is the point.
|
||||
drop(handle);
|
||||
Ok(())
|
||||
}
|
||||
@@ -0,0 +1,184 @@
|
||||
//! The audit's I/O edge: timing, JSON Lines emission, O5 accounting.
|
||||
//!
|
||||
//! Everything impure about phase 5 lives here, and it is deliberately thin —
|
||||
//! read the clock, call [`Auditor::observe`], write a line, fold a
|
||||
//! [`metrics::Sample`]. The decisions are all upstream in the pure core, which
|
||||
//! is why the matrix can be argued about in unit tests rather than only in front
|
||||
//! of a live daemon.
|
||||
//!
|
||||
//! ## Why this runs on the observer thread
|
||||
//!
|
||||
//! [`AuditSink`] is a [`ProjectionSink`], invoked inline from the PipeWire
|
||||
//! observer thread once per applied registry event. The obvious alternative —
|
||||
//! a consumer task polling
|
||||
//! [`RegistryObserverHandle::latest`](super::super::observer::adapter::RegistryObserverHandle::latest)
|
||||
//! — was rejected: polling **coalesces**, and phase 4's revocation logic
|
||||
//! detects a module unload by observing the *empty gap* before the next module
|
||||
//! appears. Module indices are reused verbatim across an unload/reload (v3.4
|
||||
//! §5.2 correction 3), so a poller that misses the gap silently aliases a fresh
|
||||
//! module onto a dead module's validated identity. Running inline is what makes
|
||||
//! "one `observe` per graph event, no coalescing" — the contract phase 4
|
||||
//! documents as owed — actually true.
|
||||
//!
|
||||
//! The cost of that choice is that recompute and logging happen on the thread
|
||||
//! servicing PipeWire, which is precisely the risk O5 asks about. That is not an
|
||||
//! accident: this arrangement puts the cost exactly where the measurement can
|
||||
//! see it. See [`metrics`].
|
||||
//!
|
||||
//! ## Output contract
|
||||
//!
|
||||
//! One JSON object per line, to **stderr** by default, each tagged with a `kind`
|
||||
//! discriminator (`"audit"` or `"metrics"`). Never stdout: peerspeak parses
|
||||
//! pixelpass's stdout event stream, and the impl plan §5 is explicit that
|
||||
//! unstructured output must not go there. `PIXELPASS_AUDIO_AUDIT_FILE`
|
||||
//! redirects the records to a file instead, which is how the §5.1 matrix is
|
||||
//! driven — it separates the audit stream from interleaved `tracing` output
|
||||
//! without needing either side to change format.
|
||||
|
||||
use std::io::Write;
|
||||
use std::time::Instant;
|
||||
|
||||
use serde::Serialize;
|
||||
|
||||
use super::metrics::{self, Metrics, Summary};
|
||||
use super::{AuditConfig, AuditRecord, Auditor};
|
||||
use crate::host::observer::adapter::ProjectionSink;
|
||||
use crate::host::observer::{EventKind, Millis, Projection};
|
||||
|
||||
/// Emit a rolling metrics line every this many ticks. Ticks are 250 ms, so this
|
||||
/// is every 10 s — often enough that a run killed abruptly still leaves a
|
||||
/// usable O5 record, rare enough that it does not crowd out the audit records.
|
||||
const SUMMARY_INTERVAL_TICKS: u64 = 40;
|
||||
|
||||
/// The live audit: pure auditor + clock + writer.
|
||||
pub struct AuditSink {
|
||||
auditor: Auditor,
|
||||
metrics: Metrics,
|
||||
writer: Box<dyn Write + Send>,
|
||||
/// Set once the first sample has completed, so the first event is not
|
||||
/// counted as having queued behind a predecessor that does not exist.
|
||||
last_completion_us: Option<u64>,
|
||||
ticks_since_summary: u64,
|
||||
/// Wall-clock origin for the microsecond timings. Only used for durations,
|
||||
/// never for the AEC deadline — that runs on the observer's own clock,
|
||||
/// handed in as `now_us`, so the validator and the readiness epoch cannot
|
||||
/// disagree about what time it is.
|
||||
epoch: Instant,
|
||||
}
|
||||
|
||||
impl AuditSink {
|
||||
pub fn new(config: AuditConfig, writer: Box<dyn Write + Send>) -> Self {
|
||||
Self {
|
||||
auditor: Auditor::new(config),
|
||||
metrics: Metrics::default(),
|
||||
writer,
|
||||
last_completion_us: None,
|
||||
ticks_since_summary: 0,
|
||||
epoch: Instant::now(),
|
||||
}
|
||||
}
|
||||
|
||||
fn elapsed_us(&self) -> u64 {
|
||||
u64::try_from(self.epoch.elapsed().as_micros()).unwrap_or(u64::MAX)
|
||||
}
|
||||
|
||||
/// Write one line. Failures are logged once per occurrence and otherwise
|
||||
/// ignored: a broken stderr must not take down the observer thread, and the
|
||||
/// audit is diagnostic — losing a line is a worse audit, not a worse share.
|
||||
fn write_line<T: Serialize>(&mut self, line: &T) {
|
||||
match serde_json::to_string(line) {
|
||||
Ok(json) => {
|
||||
if let Err(e) = writeln!(self.writer, "{json}") {
|
||||
tracing::warn!("audit: failed to write record: {e}");
|
||||
}
|
||||
}
|
||||
Err(e) => tracing::warn!("audit: failed to serialise record: {e}"),
|
||||
}
|
||||
}
|
||||
|
||||
fn write_summary(&mut self, at_ms: Millis) {
|
||||
let summary = self.metrics.summary();
|
||||
self.write_line(&MetricsLine {
|
||||
kind: "metrics",
|
||||
at_ms,
|
||||
summary: &summary,
|
||||
});
|
||||
let _ = self.writer.flush();
|
||||
}
|
||||
}
|
||||
|
||||
impl ProjectionSink for AuditSink {
|
||||
fn on_projection(&mut self, projection: &Projection, kind: EventKind, now_us: u64) {
|
||||
let at_us = self.elapsed_us();
|
||||
let gap_us = self
|
||||
.last_completion_us
|
||||
.map(|previous| at_us.saturating_sub(previous))
|
||||
.unwrap_or(0);
|
||||
|
||||
let recompute_start = self.elapsed_us();
|
||||
let outcome = self.auditor.observe(projection, kind, now_us / 1_000);
|
||||
let recompute_us = self.elapsed_us().saturating_sub(recompute_start);
|
||||
|
||||
let emit_us = if outcome.emit {
|
||||
let emit_start = self.elapsed_us();
|
||||
self.write_line(&AuditLine {
|
||||
kind: "audit",
|
||||
recompute_us,
|
||||
record: &outcome.record,
|
||||
});
|
||||
// Flushed per record so a run ended with SIGKILL (or a matrix row
|
||||
// that reads the file while the process is still up) still shows
|
||||
// every decision made before that instant. The cost is measured, not
|
||||
// assumed — it is inside `emit_us`.
|
||||
let _ = self.writer.flush();
|
||||
self.elapsed_us().saturating_sub(emit_start).max(1)
|
||||
} else {
|
||||
0
|
||||
};
|
||||
|
||||
self.metrics.record(metrics::Sample {
|
||||
at_us,
|
||||
gap_us,
|
||||
recompute_us,
|
||||
emit_us,
|
||||
kind,
|
||||
});
|
||||
self.last_completion_us = Some(self.elapsed_us());
|
||||
|
||||
if kind == EventKind::Tick {
|
||||
self.ticks_since_summary += 1;
|
||||
if self.ticks_since_summary >= SUMMARY_INTERVAL_TICKS {
|
||||
self.ticks_since_summary = 0;
|
||||
self.write_summary(now_us / 1_000);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl Drop for AuditSink {
|
||||
/// The final O5 record. The observer thread drops its sink when the main
|
||||
/// loop quits, so an ordinary ctrl-c leaves a complete summary behind
|
||||
/// without the runner having to ask for one.
|
||||
fn drop(&mut self) {
|
||||
let at_ms = self.elapsed_us() / 1_000;
|
||||
self.write_summary(at_ms);
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Serialize)]
|
||||
struct AuditLine<'a> {
|
||||
kind: &'static str,
|
||||
/// This record's own recompute cost, so a surprising row can be correlated
|
||||
/// with a cost spike without cross-referencing the periodic summary.
|
||||
recompute_us: u64,
|
||||
#[serde(flatten)]
|
||||
record: &'a AuditRecord,
|
||||
}
|
||||
|
||||
#[derive(Serialize)]
|
||||
struct MetricsLine<'a> {
|
||||
kind: &'static str,
|
||||
at_ms: Millis,
|
||||
#[serde(flatten)]
|
||||
summary: &'a Summary,
|
||||
}
|
||||
@@ -0,0 +1,960 @@
|
||||
//! Pure tests for the phase-5 auditor and its O5 metrics.
|
||||
//!
|
||||
//! Two things are being tested here and they are worth keeping distinct:
|
||||
//!
|
||||
//! - **Audit-layer behaviour** — the fan-out gate, record suppression, sequence
|
||||
//! accounting, epoch reporting, and above all that every record carries the
|
||||
//! *complete* candidate universe (§5.1). These are properties nothing else
|
||||
//! tests, because nothing else exists at this layer.
|
||||
//! - **A few §5.1 matrix shapes in fixture form** — row 1 (owner-bridge
|
||||
//! forwarder), row 3 (two modules, one tainted), row 12 (AEC lifecycle). These
|
||||
//! are *not* re-litigating phase 2, whose 57 tests already own those verdicts.
|
||||
//! They exist so that a plumbing mistake between the engine and the record —
|
||||
//! a dropped reason code, an inverted partition — fails here, at compile-time
|
||||
//! speed, rather than only in front of a live daemon.
|
||||
//!
|
||||
//! The live half of the gate cannot live in this file by definition: a fixture
|
||||
//! tests my model against my own assumptions, and §5's whole argument is that
|
||||
//! only a live run tests my model against PipeWire. See the matrix runs recorded
|
||||
//! in the phase-5 results file.
|
||||
|
||||
use super::metrics::{BUCKET_LABELS, Metrics, QUEUE_THRESHOLD_US, Sample};
|
||||
use super::*;
|
||||
use crate::host::aec::AecConfig;
|
||||
use crate::host::observer::{EventKind, Readiness};
|
||||
use crate::host::taint::PEERSPEAK_OWNED_NODE_PREFIX;
|
||||
use crate::host::taint::fixture::{self, Graph, NodeRef};
|
||||
use crate::host::taint::snapshot::{GraphSnapshot, MediaRole};
|
||||
|
||||
/// The `node.name` a [`Graph::peerspeak_node`] fixture produces. Built from
|
||||
/// the same constant the engine matches on, so these audit rows report the
|
||||
/// name shape a live peerspeak node actually has (v3.5 §5.1, carrier 2).
|
||||
fn owned_name(role: &str, pid: u32) -> String {
|
||||
format!("{PEERSPEAK_OWNED_NODE_PREFIX}{role}_{pid}")
|
||||
}
|
||||
|
||||
const AEC_MODULE: u64 = 7;
|
||||
const TIMEOUT: Millis = 5_000;
|
||||
|
||||
fn ready(snapshot: GraphSnapshot) -> Projection {
|
||||
Projection {
|
||||
snapshot,
|
||||
pipewire_pulse_pid: Some(fixture::PULSE_PID),
|
||||
graph_ready: true,
|
||||
readiness: Readiness::Complete,
|
||||
}
|
||||
}
|
||||
|
||||
fn not_ready(snapshot: GraphSnapshot, readiness: Readiness) -> Projection {
|
||||
Projection {
|
||||
snapshot,
|
||||
pipewire_pulse_pid: Some(fixture::PULSE_PID),
|
||||
graph_ready: false,
|
||||
readiness,
|
||||
}
|
||||
}
|
||||
|
||||
fn auditor_off() -> Auditor {
|
||||
Auditor::new(AuditConfig {
|
||||
aec: AecConfig::Off,
|
||||
aec_timeout: TIMEOUT,
|
||||
})
|
||||
}
|
||||
|
||||
fn auditor_aec(index: u64) -> Auditor {
|
||||
Auditor::new(AuditConfig {
|
||||
aec: AecConfig::PulseModule(index),
|
||||
aec_timeout: TIMEOUT,
|
||||
})
|
||||
}
|
||||
|
||||
/// One graph-triggered recompute at `now`.
|
||||
fn observe(auditor: &mut Auditor, projection: &Projection, now: Millis) -> AuditOutcome {
|
||||
auditor.observe(projection, EventKind::Graph, now)
|
||||
}
|
||||
|
||||
/// Candidate names split into (eligible, excluded-with-reason), which is how the
|
||||
/// §5.1 rows are phrased. Names rather than serials so a failure reads as the
|
||||
/// scenario rather than as an integer.
|
||||
fn partition(body: &AuditBody) -> (Vec<&str>, Vec<(&str, &str)>) {
|
||||
let eligible = body
|
||||
.candidates
|
||||
.iter()
|
||||
.filter(|row| row.eligible)
|
||||
.map(|row| row.name.as_deref().unwrap_or("<unnamed>"))
|
||||
.collect();
|
||||
let excluded = body
|
||||
.candidates
|
||||
.iter()
|
||||
.filter(|row| !row.eligible)
|
||||
.map(|row| {
|
||||
(
|
||||
row.name.as_deref().unwrap_or("<unnamed>"),
|
||||
row.reason.unwrap_or("<none>"),
|
||||
)
|
||||
})
|
||||
.collect();
|
||||
(eligible, excluded)
|
||||
}
|
||||
|
||||
// ── the §5.1 structural requirement ───────────────────────────────────────
|
||||
|
||||
/// The record must contain **every** `Stream/Output/Audio` node, not only the
|
||||
/// interesting ones. This is the property the whole exact-partition requirement
|
||||
/// rests on: if the record could omit a candidate, then asserting a complete
|
||||
/// partition over the record would still not constrain the graph.
|
||||
#[test]
|
||||
fn the_record_carries_the_complete_candidate_universe() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
graph.app_node("game", MediaRole::StreamOutput, 101);
|
||||
graph.app_node("recorder", MediaRole::StreamInput, 102);
|
||||
graph.device_node("speakers", MediaRole::Sink);
|
||||
let projection = ready(graph.build());
|
||||
|
||||
let outcome = observe(&mut auditor_off(), &projection, 0);
|
||||
let (eligible, excluded) = partition(&outcome.record.body);
|
||||
|
||||
// Both playback streams, neither the capture stream nor the sink. Ordered by
|
||||
// serial (creation order), which is what makes the partition assertions in
|
||||
// every other row stable rather than dependent on a hash iteration.
|
||||
assert_eq!(eligible, vec!["music", "game"]);
|
||||
assert!(excluded.is_empty(), "unexpected exclusions: {excluded:?}");
|
||||
assert_eq!(outcome.record.body.candidates.len(), 2);
|
||||
assert_eq!(outcome.record.body.eligible_count, 2);
|
||||
assert_eq!(outcome.record.body.excluded_count, 0);
|
||||
}
|
||||
|
||||
/// **R10-1's diagnostic reaches the record.** The engine deliberately ignores
|
||||
/// an ownership carrier on a non-producer, which means the fix removes an
|
||||
/// exclusion — so the only way an operator learns a tag was seen and dropped is
|
||||
/// this field. A matrix row that silently grew an impostor would otherwise read
|
||||
/// as a clean pass.
|
||||
#[test]
|
||||
fn an_ignored_ownership_tag_is_reported_without_excluding_anything() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
let impostor = graph.peerspeak_tagged_node("rogue", MediaRole::StreamInput, 4_242);
|
||||
let projection = ready(graph.build());
|
||||
|
||||
let body = observe(&mut auditor_off(), &projection, 0).record.body;
|
||||
|
||||
// The bystander is untouched — the point of the fix.
|
||||
let (eligible, excluded) = partition(&body);
|
||||
assert_eq!(eligible, vec!["music"]);
|
||||
assert!(excluded.is_empty(), "unexpected exclusions: {excluded:?}");
|
||||
assert!(body.taint.is_empty(), "unexpected taint: {:?}", body.taint);
|
||||
|
||||
// ...but the tag is not silent, and the row names the role it appeared on.
|
||||
assert_eq!(body.ignored_ownership_tags.len(), 1);
|
||||
let row = &body.ignored_ownership_tags[0];
|
||||
assert_eq!(row.serial, impostor.serial.0);
|
||||
assert_eq!(row.role, "stream-input");
|
||||
assert_eq!(
|
||||
row.name.as_deref(),
|
||||
Some(owned_name("rogue", 4_242).as_str())
|
||||
);
|
||||
}
|
||||
|
||||
/// The common path stays quiet: a correctly tagged peerspeak producer is
|
||||
/// honoured as a taint root and is *not* reported as a misplaced tag. Without
|
||||
/// this, a diagnostic that fired on every normal run would be worthless.
|
||||
#[test]
|
||||
fn a_correctly_tagged_producer_is_not_reported_as_misplaced() {
|
||||
let mut graph = Graph::new();
|
||||
let sink = graph.device_node("speakers", MediaRole::Sink);
|
||||
let call = graph.peerspeak_node("call", 200);
|
||||
graph.link(call, sink);
|
||||
let projection = ready(graph.build());
|
||||
|
||||
let body = observe(&mut auditor_off(), &projection, 0).record.body;
|
||||
|
||||
assert_eq!(body.excluded_count, 1);
|
||||
assert!(
|
||||
body.ignored_ownership_tags.is_empty(),
|
||||
"honoured tag reported as misplaced: {:?}",
|
||||
body.ignored_ownership_tags
|
||||
);
|
||||
}
|
||||
|
||||
/// The fail-closed default asserted at the boundary (impl plan §4, phase 2's
|
||||
/// "one addition"): nothing in, nothing eligible — and, just as importantly, no
|
||||
/// panic and no invented row.
|
||||
#[test]
|
||||
fn an_empty_graph_yields_an_empty_partition() {
|
||||
let projection = ready(Graph::new().build());
|
||||
let outcome = observe(&mut auditor_off(), &projection, 0);
|
||||
|
||||
assert!(outcome.record.body.candidates.is_empty());
|
||||
assert!(outcome.record.body.taint.is_empty());
|
||||
assert_eq!(outcome.record.body.eligible_count, 0);
|
||||
assert_eq!(outcome.record.body.excluded_count, 0);
|
||||
assert!(outcome.record.body.fan_out_permitted);
|
||||
}
|
||||
|
||||
/// `eligible_count + excluded_count` is the candidate count, always. A partition
|
||||
/// that does not partition would let a row's two assertions both pass while the
|
||||
/// record described no coherent state.
|
||||
#[test]
|
||||
fn the_counts_always_partition_the_candidates() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
graph.peerspeak_node("peerspeak-playback", 200);
|
||||
let projection = ready(graph.build());
|
||||
|
||||
let body = observe(&mut auditor_off(), &projection, 0).record.body;
|
||||
assert_eq!(
|
||||
body.eligible_count + body.excluded_count,
|
||||
body.candidates.len()
|
||||
);
|
||||
assert_eq!(body.eligible().len(), body.eligible_count);
|
||||
assert_eq!(body.excluded().len(), body.excluded_count);
|
||||
}
|
||||
|
||||
/// Every excluded row names a reason and every eligible row does not. The
|
||||
/// §5.1 rows assert "excluded, with reason code" — a `None` reason on an
|
||||
/// excluded row would make that assertion unwritable.
|
||||
#[test]
|
||||
fn reason_presence_is_exactly_the_exclusion() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
graph.peerspeak_node("peerspeak-playback", 200);
|
||||
let projection = ready(graph.build());
|
||||
|
||||
for row in observe(&mut auditor_off(), &projection, 0)
|
||||
.record
|
||||
.body
|
||||
.candidates
|
||||
{
|
||||
assert_eq!(
|
||||
row.eligible,
|
||||
row.reason.is_none(),
|
||||
"row {row:?} has eligibility and reason out of step"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// ── readiness ─────────────────────────────────────────────────────────────
|
||||
|
||||
/// No decision made from a partial graph is a decision. Note this is asserted on
|
||||
/// the *eligible* half too: an implementation that reported nothing at all while
|
||||
/// not ready would also be wrong, because the audit must still show what it can
|
||||
/// see.
|
||||
#[test]
|
||||
fn a_not_ready_graph_excludes_every_candidate() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
graph.app_node("game", MediaRole::StreamOutput, 101);
|
||||
let projection = not_ready(graph.build(), Readiness::Waiting);
|
||||
|
||||
let body = observe(&mut auditor_off(), &projection, 0).record.body;
|
||||
let (eligible, excluded) = partition(&body);
|
||||
|
||||
assert!(eligible.is_empty());
|
||||
assert_eq!(
|
||||
excluded,
|
||||
vec![("music", "graph-not-ready"), ("game", "graph-not-ready"),]
|
||||
);
|
||||
assert!(!body.graph_ready);
|
||||
}
|
||||
|
||||
/// The three ways `graph_ready` can be false are distinguishable in the record.
|
||||
/// Collapsing them would make a timed-out observer — a fail-closed *fault* —
|
||||
/// indistinguishable from an enumeration that is merely still running.
|
||||
#[test]
|
||||
fn the_epoch_distinguishes_the_ways_a_graph_can_be_unready() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
let snapshot = graph.build();
|
||||
|
||||
for (readiness, expected) in [
|
||||
(Readiness::Waiting, "waiting"),
|
||||
(Readiness::TimedOut, "timed-out"),
|
||||
// A completed epoch momentarily blocked on a current obligation: the
|
||||
// interesting one, because `graph_ready` alone makes it look like a
|
||||
// brand-new observer.
|
||||
(Readiness::Complete, "complete"),
|
||||
] {
|
||||
let projection = not_ready(snapshot.clone(), readiness);
|
||||
let body = observe(&mut auditor_off(), &projection, 0).record.body;
|
||||
assert_eq!(body.epoch, expected);
|
||||
assert!(!body.graph_ready);
|
||||
}
|
||||
|
||||
let body = observe(&mut auditor_off(), &ready(snapshot), 0).record.body;
|
||||
assert_eq!(body.epoch, "complete");
|
||||
assert!(body.graph_ready);
|
||||
}
|
||||
|
||||
// ── the fan-out gate (phase 4 → audit) ────────────────────────────────────
|
||||
|
||||
/// `--aec=off` leaves the gate open: `NotConfigured` is "there is no echo
|
||||
/// canceller", not "we failed to find one".
|
||||
#[test]
|
||||
fn aec_off_leaves_the_gate_open() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
let projection = ready(graph.build());
|
||||
|
||||
let body = observe(&mut auditor_off(), &projection, 0).record.body;
|
||||
assert_eq!(body.aec_state, "not-configured");
|
||||
assert!(body.fan_out_permitted);
|
||||
assert_eq!(body.gate_reason, None);
|
||||
assert_eq!(body.aec_module_id, None);
|
||||
assert_eq!(partition(&body).0, vec!["music"]);
|
||||
}
|
||||
|
||||
/// While the configured identity has not been seen, nothing may fan out —
|
||||
/// silence over echo — and the record says why in a code, not in prose.
|
||||
#[test]
|
||||
fn a_validating_gate_excludes_every_engine_eligible_candidate() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
graph.app_node("game", MediaRole::StreamOutput, 101);
|
||||
let projection = ready(graph.build());
|
||||
|
||||
let body = observe(&mut auditor_aec(AEC_MODULE), &projection, 0)
|
||||
.record
|
||||
.body;
|
||||
let (eligible, excluded) = partition(&body);
|
||||
|
||||
assert_eq!(body.aec_state, "validating");
|
||||
assert!(!body.fan_out_permitted);
|
||||
assert_eq!(body.gate_reason, Some("aec-validating"));
|
||||
assert!(eligible.is_empty());
|
||||
assert_eq!(
|
||||
excluded,
|
||||
vec![("music", "aec-validating"), ("game", "aec-validating")]
|
||||
);
|
||||
}
|
||||
|
||||
/// A shut gate must not erase the engine's own reason codes. If it did, every
|
||||
/// §5.1 row run under a shut gate would report one uniform code and the matrix
|
||||
/// would stop constraining the taint engine at all — the record would say
|
||||
/// "nothing may fan out" while hiding *which* nodes were tainted and how.
|
||||
#[test]
|
||||
fn a_shut_gate_preserves_the_engines_own_reasons() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
graph.peerspeak_node("peerspeak-playback", 200);
|
||||
let projection = ready(graph.build());
|
||||
|
||||
let body = observe(&mut auditor_aec(AEC_MODULE), &projection, 0)
|
||||
.record
|
||||
.body;
|
||||
let (_, excluded) = partition(&body);
|
||||
|
||||
let playback = owned_name("peerspeak-playback", 200);
|
||||
assert!(!body.fan_out_permitted);
|
||||
assert_eq!(
|
||||
excluded,
|
||||
vec![
|
||||
("music", "aec-validating"),
|
||||
// Tagged, so it keeps the reason that actually applies to it.
|
||||
(playback.as_str(), "peerspeak-owned"),
|
||||
]
|
||||
);
|
||||
}
|
||||
|
||||
/// The deadline is armed on the first ready graph, so a slow enumeration reads
|
||||
/// as "unknown", not "absent" (the phase-4 user design call). Past it with the
|
||||
/// identity never seen, the gate latches shut.
|
||||
#[test]
|
||||
fn the_gate_fails_closed_after_the_deadline() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
let snapshot = graph.build();
|
||||
let mut auditor = auditor_aec(AEC_MODULE);
|
||||
|
||||
// Still enumerating well past the timeout: not a failure, because absence
|
||||
// has not been established.
|
||||
let waiting = not_ready(snapshot.clone(), Readiness::Waiting);
|
||||
let body = observe(&mut auditor, &waiting, TIMEOUT * 3).record.body;
|
||||
assert_eq!(body.aec_state, "validating");
|
||||
|
||||
// Ready arms the deadline; the clock has to advance past it from here.
|
||||
let projection = ready(snapshot);
|
||||
let body = observe(&mut auditor, &projection, TIMEOUT * 3).record.body;
|
||||
assert_eq!(body.aec_state, "validating");
|
||||
|
||||
let body = observe(&mut auditor, &projection, TIMEOUT * 6 + 1)
|
||||
.record
|
||||
.body;
|
||||
assert_eq!(body.aec_state, "failed");
|
||||
assert_eq!(body.gate_reason, Some("aec-failed"));
|
||||
assert_eq!(partition(&body).1, vec![("music", "aec-failed")]);
|
||||
}
|
||||
|
||||
// ── §5.1 row 12: the AEC lifecycle ────────────────────────────────────────
|
||||
|
||||
/// Build the four nodes `module-echo-cancel` creates, all bearing one index:
|
||||
/// two `Stream/*` legs plus the virtual sink/source pair (v3.4 §5.2). The
|
||||
/// playback leg is the hazard — a `Stream/Output/Audio` wired to the speakers.
|
||||
fn aec_nodes(graph: &mut Graph, index: u64) -> Vec<NodeRef> {
|
||||
vec![
|
||||
graph.module_node("echo-cancel-playback", MediaRole::StreamOutput, index),
|
||||
graph.module_node("echo-cancel-capture", MediaRole::StreamInput, index),
|
||||
graph.module_node("echo-cancel-sink", MediaRole::Sink, index),
|
||||
graph.module_node("echo-cancel-source", MediaRole::Source, index),
|
||||
]
|
||||
}
|
||||
|
||||
/// §5.1 row 12: AEC loaded → validated, its playback leg excluded by identity
|
||||
/// while everything else stays eligible → unloaded → `Revoked`, gate shut.
|
||||
///
|
||||
/// The eligible half is the load-bearing assertion in the first phase: an
|
||||
/// implementation that excluded the whole graph the moment an AEC appeared would
|
||||
/// satisfy "the four nodes are excluded" and still be wrong.
|
||||
#[test]
|
||||
fn row_12_aec_loaded_then_unloaded_validates_then_revokes() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
let aec = aec_nodes(&mut graph, AEC_MODULE);
|
||||
let mut auditor = auditor_aec(AEC_MODULE);
|
||||
|
||||
let loaded = ready(graph.build());
|
||||
let body = observe(&mut auditor, &loaded, 0).record.body;
|
||||
let (eligible, excluded) = partition(&body);
|
||||
|
||||
assert_eq!(body.aec_state, "validated");
|
||||
assert!(body.fan_out_permitted);
|
||||
assert_eq!(body.aec_module_id, Some(AEC_MODULE));
|
||||
assert_eq!(eligible, vec!["music"]);
|
||||
assert_eq!(excluded, vec![("echo-cancel-playback", "aec-identity")]);
|
||||
|
||||
// Every node bearing the index goes away: a real unload.
|
||||
let unloaded = ready(graph.build_without(&aec));
|
||||
let body = observe(&mut auditor, &unloaded, 1).record.body;
|
||||
let (eligible, excluded) = partition(&body);
|
||||
|
||||
assert_eq!(body.aec_state, "revoked");
|
||||
assert!(!body.fan_out_permitted);
|
||||
assert_eq!(body.gate_reason, Some("aec-revoked"));
|
||||
assert_eq!(body.aec_module_id, None);
|
||||
assert!(eligible.is_empty());
|
||||
assert_eq!(excluded, vec![("music", "aec-revoked")]);
|
||||
}
|
||||
|
||||
/// One leg corking is not a revocation (v3.4 §5.3). Getting this wrong turns an
|
||||
/// ordinary cork into a share-wide audio stop, so the audit must report the
|
||||
/// identity as still live.
|
||||
#[test]
|
||||
fn row_12_partial_leg_loss_does_not_revoke() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
let aec = aec_nodes(&mut graph, AEC_MODULE);
|
||||
let mut auditor = auditor_aec(AEC_MODULE);
|
||||
|
||||
let body = observe(&mut auditor, &ready(graph.build()), 0).record.body;
|
||||
assert_eq!(body.aec_state, "validated");
|
||||
|
||||
// The capture leg alone disappears; three nodes still bear the index.
|
||||
let partial = ready(graph.build_without(&aec[1..2]));
|
||||
let body = observe(&mut auditor, &partial, 1).record.body;
|
||||
|
||||
assert_eq!(body.aec_state, "validated");
|
||||
assert!(body.fan_out_permitted);
|
||||
assert_eq!(partition(&body).0, vec!["music"]);
|
||||
}
|
||||
|
||||
/// Revocation is sticky terminal: module indices are reused verbatim across an
|
||||
/// unload/reload (v3.4 §5.2 correction 3), so a reappearing index must not
|
||||
/// resurrect the epoch and alias onto an unrelated module. A genuine reload gets
|
||||
/// a fresh validator, never this one.
|
||||
#[test]
|
||||
fn row_12_a_reused_index_does_not_resurrect_a_revoked_epoch() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
let aec = aec_nodes(&mut graph, AEC_MODULE);
|
||||
let mut auditor = auditor_aec(AEC_MODULE);
|
||||
|
||||
observe(&mut auditor, &ready(graph.build()), 0);
|
||||
let unloaded = graph.build_without(&aec);
|
||||
let body = observe(&mut auditor, &ready(unloaded), 1).record.body;
|
||||
assert_eq!(body.aec_state, "revoked");
|
||||
|
||||
// A second module comes back with the same index — different objects,
|
||||
// identical number.
|
||||
let mut reloaded = Graph::new();
|
||||
reloaded.app_node("music", MediaRole::StreamOutput, 100);
|
||||
aec_nodes(&mut reloaded, AEC_MODULE);
|
||||
let body = observe(&mut auditor, &ready(reloaded.build()), 2)
|
||||
.record
|
||||
.body;
|
||||
|
||||
assert_eq!(body.aec_state, "revoked");
|
||||
assert!(!body.fan_out_permitted);
|
||||
assert_eq!(body.gate_reason, Some("aec-revoked"));
|
||||
}
|
||||
|
||||
// ── §5.1 rows in fixture form (plumbing, not phase-2 verdicts) ────────────
|
||||
|
||||
/// §5.1 row 1: a `module-null-sink` + `module-loopback` forwarder. The output
|
||||
/// leg is excluded across the **owner bridge** — naming the mechanism, not a
|
||||
/// link walk — while an identically-shaped forwarder with no tainted input stays
|
||||
/// eligible. The second half is what an exclude-everything build fails.
|
||||
#[test]
|
||||
fn row_1_owner_bridge_forwarder_with_an_untainted_control() {
|
||||
let mut graph = Graph::new();
|
||||
// Tainted root: peerspeak's own call playback, feeding a sink the forwarder
|
||||
// reads back out.
|
||||
let call = graph.peerspeak_node("peerspeak-call", 200);
|
||||
let sink = graph.module_node("tainted-null-sink", MediaRole::Sink, 30);
|
||||
graph.link(call, sink);
|
||||
let capture = graph.module_node("tainted-loopback-capture", MediaRole::StreamInput, 30);
|
||||
let playback = graph.module_node("tainted-loopback-playback", MediaRole::StreamOutput, 30);
|
||||
graph.link(sink, capture);
|
||||
let _ = playback;
|
||||
|
||||
// Control: the same shape, fed by nothing tainted.
|
||||
let clean_sink = graph.module_node("clean-null-sink", MediaRole::Sink, 31);
|
||||
let clean_capture = graph.module_node("clean-loopback-capture", MediaRole::StreamInput, 31);
|
||||
let clean_playback = graph.module_node("clean-loopback-playback", MediaRole::StreamOutput, 31);
|
||||
graph.link(clean_sink, clean_capture);
|
||||
let _ = clean_playback;
|
||||
|
||||
let body = observe(&mut auditor_off(), &ready(graph.build()), 0)
|
||||
.record
|
||||
.body;
|
||||
let (eligible, excluded) = partition(&body);
|
||||
|
||||
let call_name = owned_name("peerspeak-call", 200);
|
||||
assert_eq!(eligible, vec!["clean-loopback-playback"]);
|
||||
assert_eq!(
|
||||
excluded,
|
||||
vec![
|
||||
(call_name.as_str(), "peerspeak-owned"),
|
||||
("tainted-loopback-playback", "tainted-owner-bridge"),
|
||||
]
|
||||
);
|
||||
}
|
||||
|
||||
/// §5.1 row 3: two Pulse modules, one tainted input. **The other module's output
|
||||
/// must be eligible** — this is the row that makes a wrong pipewire-pulse-PID
|
||||
/// fusion observable, because fusing all Pulse-created nodes into one owner
|
||||
/// would drag the innocent module's output leg down with the tainted one.
|
||||
#[test]
|
||||
fn row_3_one_tainted_module_does_not_taint_the_other() {
|
||||
let mut graph = Graph::new();
|
||||
let call = graph.peerspeak_node("peerspeak-call", 200);
|
||||
let sink = graph.module_node("null-sink-a", MediaRole::Sink, 40);
|
||||
graph.link(call, sink);
|
||||
let capture_a = graph.module_node("module-a-capture", MediaRole::StreamInput, 40);
|
||||
let playback_a = graph.module_node("module-a-playback", MediaRole::StreamOutput, 40);
|
||||
graph.link(sink, capture_a);
|
||||
let _ = playback_a;
|
||||
|
||||
// A second, entirely independent module reading an untainted source.
|
||||
let mic = graph.device_node("microphone", MediaRole::Source);
|
||||
let capture_b = graph.module_node("module-b-capture", MediaRole::StreamInput, 41);
|
||||
let playback_b = graph.module_node("module-b-playback", MediaRole::StreamOutput, 41);
|
||||
graph.link(mic, capture_b);
|
||||
let _ = playback_b;
|
||||
|
||||
let body = observe(&mut auditor_off(), &ready(graph.build()), 0)
|
||||
.record
|
||||
.body;
|
||||
let (eligible, excluded) = partition(&body);
|
||||
|
||||
let call_name = owned_name("peerspeak-call", 200);
|
||||
assert_eq!(eligible, vec!["module-b-playback"]);
|
||||
assert_eq!(
|
||||
excluded,
|
||||
vec![
|
||||
(call_name.as_str(), "peerspeak-owned"),
|
||||
("module-a-playback", "tainted-owner-bridge"),
|
||||
]
|
||||
);
|
||||
}
|
||||
|
||||
/// §5.1 row 7 (cycle prevention, v3.4 §6.2): a forwarder reading *another*
|
||||
/// pixelpass host's capture sink must be excluded by its **named output
|
||||
/// serial**, or two hosts sharing to each other build an audio cycle.
|
||||
#[test]
|
||||
fn row_7_a_forwarder_reading_another_hosts_capture_sink_is_excluded() {
|
||||
let mut graph = Graph::new();
|
||||
// The other host's own client, in *this* graph — a node pointing at a client
|
||||
// that does not exist would exercise the unresolved-owner path instead of the
|
||||
// capture-sink-name path this row is about.
|
||||
let other_client = graph.client(Some(fixture::PULSE_PID));
|
||||
let other_sink = graph.node(
|
||||
"pixelpass_capture_deadbeef",
|
||||
MediaRole::Sink,
|
||||
fixture::app(other_client, 300),
|
||||
);
|
||||
let capture = graph.module_node("cycle-loopback-capture", MediaRole::StreamInput, 50);
|
||||
let playback = graph.module_node("cycle-loopback-playback", MediaRole::StreamOutput, 50);
|
||||
graph.link(other_sink, capture);
|
||||
let _ = playback;
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
|
||||
let body = observe(&mut auditor_off(), &ready(graph.build()), 0)
|
||||
.record
|
||||
.body;
|
||||
let (eligible, excluded) = partition(&body);
|
||||
|
||||
assert_eq!(eligible, vec!["music"]);
|
||||
assert_eq!(
|
||||
excluded,
|
||||
vec![("cycle-loopback-playback", "tainted-owner-bridge")]
|
||||
);
|
||||
// The sink itself is tainted, by the mechanism that names it.
|
||||
let sink_taint = body
|
||||
.taint
|
||||
.iter()
|
||||
.find(|row| row.name.as_deref() == Some("pixelpass_capture_deadbeef"))
|
||||
.expect("the other host's capture sink must be tainted");
|
||||
assert_eq!(sink_taint.reason, "pixelpass-owned");
|
||||
}
|
||||
|
||||
/// Sticky taint (§5.1 row 10) is reported as sticky, not silently folded into
|
||||
/// an ordinary exclusion. The flag is how the audit distinguishes "this is
|
||||
/// tainted right now" from "this was tainted and its owner has not fully torn
|
||||
/// down" — two different things to be surprised by.
|
||||
#[test]
|
||||
fn sticky_exclusions_are_flagged_as_sticky() {
|
||||
let mut graph = Graph::new();
|
||||
let call = graph.peerspeak_node("peerspeak-call", 200);
|
||||
let sink = graph.module_node("null-sink", MediaRole::Sink, 60);
|
||||
graph.link(call, sink);
|
||||
let capture = graph.module_node("loopback-capture", MediaRole::StreamInput, 60);
|
||||
graph.module_node("loopback-playback", MediaRole::StreamOutput, 60);
|
||||
graph.link(sink, capture);
|
||||
|
||||
let mut auditor = auditor_off();
|
||||
let body = observe(&mut auditor, &ready(graph.build()), 0).record.body;
|
||||
let playback = body
|
||||
.row_named("loopback-playback")
|
||||
.expect("the output leg must be a candidate");
|
||||
assert!(!playback.eligible);
|
||||
assert!(!playback.sticky, "first sight is not sticky");
|
||||
|
||||
// The tainted input leg goes away; the output leg lives on.
|
||||
let body = observe(&mut auditor, &ready(graph.build_without(&[capture])), 1)
|
||||
.record
|
||||
.body;
|
||||
let playback = body
|
||||
.row_named("loopback-playback")
|
||||
.expect("the output leg must still be a candidate");
|
||||
assert!(!playback.eligible);
|
||||
assert!(playback.sticky, "the taint is carried over, and says so");
|
||||
}
|
||||
|
||||
// ── record accounting ─────────────────────────────────────────────────────
|
||||
|
||||
/// Ticks exist to drive the AEC deadline, not to describe the graph. Emitting an
|
||||
/// identical record four times a second would bury the graph events the audit
|
||||
/// exists to show — but a tick that *does* change something must still be
|
||||
/// emitted, or a `Validating → Failed` transition (which only a tick can cause)
|
||||
/// would never appear in the log at all.
|
||||
#[test]
|
||||
fn an_unchanged_tick_is_suppressed_but_a_changed_one_is_not() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
let projection = ready(graph.build());
|
||||
let mut auditor = auditor_aec(AEC_MODULE);
|
||||
|
||||
assert!(auditor.observe(&projection, EventKind::Graph, 0).emit);
|
||||
assert!(
|
||||
!auditor.observe(&projection, EventKind::Tick, 100).emit,
|
||||
"an identical tick record is noise"
|
||||
);
|
||||
assert!(
|
||||
!auditor.observe(&projection, EventKind::Tick, 200).emit,
|
||||
"still noise"
|
||||
);
|
||||
|
||||
// The deadline expires on a tick: the state changes, so this one is emitted.
|
||||
let outcome = auditor.observe(&projection, EventKind::Tick, TIMEOUT + 1);
|
||||
assert!(outcome.emit);
|
||||
assert_eq!(outcome.record.body.aec_state, "failed");
|
||||
}
|
||||
|
||||
/// A graph event always emits, even when the decision content is identical — a
|
||||
/// suppressed graph event would erase the evidence that the graph changed at all,
|
||||
/// and "PipeWire told us something and nothing moved" is itself a finding.
|
||||
#[test]
|
||||
fn an_unchanged_graph_event_still_emits() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
let projection = ready(graph.build());
|
||||
let mut auditor = auditor_off();
|
||||
|
||||
assert!(observe(&mut auditor, &projection, 0).emit);
|
||||
assert!(observe(&mut auditor, &projection, 1).emit);
|
||||
}
|
||||
|
||||
/// `seq` counts every recompute, emitted or not, so a gap in the emitted
|
||||
/// sequence is visibly a suppression rather than a lost line. Without this, a
|
||||
/// reader cannot tell a quiet audit from a broken one.
|
||||
#[test]
|
||||
fn seq_counts_suppressed_recomputes_too() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
let projection = ready(graph.build());
|
||||
let mut auditor = auditor_off();
|
||||
|
||||
assert_eq!(observe(&mut auditor, &projection, 0).record.seq, 1);
|
||||
let suppressed = auditor.observe(&projection, EventKind::Tick, 1);
|
||||
assert!(!suppressed.emit);
|
||||
assert_eq!(suppressed.record.seq, 2);
|
||||
assert_eq!(observe(&mut auditor, &projection, 2).record.seq, 3);
|
||||
}
|
||||
|
||||
/// Suppression compares against the last record actually *written*, not the last
|
||||
/// one computed. Comparing against the last computed record would let a change
|
||||
/// that appears and reverts between two ticks vanish from the log entirely,
|
||||
/// leaving a reader with a record that no longer matches the state.
|
||||
#[test]
|
||||
fn suppression_compares_against_the_last_emitted_record() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("music", MediaRole::StreamOutput, 100);
|
||||
let with_music = ready(graph.build());
|
||||
let empty = ready(Graph::new().build());
|
||||
let mut auditor = auditor_off();
|
||||
|
||||
assert!(observe(&mut auditor, &with_music, 0).emit);
|
||||
// A tick sees a different graph and emits.
|
||||
assert!(auditor.observe(&empty, EventKind::Tick, 1).emit);
|
||||
// The next tick sees the original graph again — different from what was last
|
||||
// written, so it must be emitted.
|
||||
assert!(auditor.observe(&with_music, EventKind::Tick, 2).emit);
|
||||
// And now it matches the last written record.
|
||||
assert!(!auditor.observe(&with_music, EventKind::Tick, 3).emit);
|
||||
}
|
||||
|
||||
/// The trigger and clock are reported verbatim, which is what lets the O5 event
|
||||
/// rate be recomputed from the record stream alone rather than trusted from the
|
||||
/// summary.
|
||||
#[test]
|
||||
fn the_record_reports_its_trigger_and_clock() {
|
||||
let projection = ready(Graph::new().build());
|
||||
let mut auditor = auditor_off();
|
||||
|
||||
let outcome = auditor.observe(&projection, EventKind::Graph, 42);
|
||||
assert_eq!(outcome.record.trigger, "graph");
|
||||
assert_eq!(outcome.record.at_ms, 42);
|
||||
|
||||
let outcome = auditor.observe(&projection, EventKind::Tick, 43);
|
||||
assert_eq!(outcome.record.trigger, "tick");
|
||||
assert_eq!(outcome.record.at_ms, 43);
|
||||
}
|
||||
|
||||
/// The taint view spans every media role, not just candidates. A candidate's
|
||||
/// exclusion is usually explained by taint on a node that is not itself a
|
||||
/// candidate — the sink in the middle of a forwarder — and without that the
|
||||
/// record shows the verdict but not the evidence.
|
||||
#[test]
|
||||
fn the_taint_view_covers_non_candidate_roles() {
|
||||
let mut graph = Graph::new();
|
||||
let call = graph.peerspeak_node("peerspeak-call", 200);
|
||||
let sink = graph.module_node("null-sink", MediaRole::Sink, 70);
|
||||
graph.link(call, sink);
|
||||
|
||||
let body = observe(&mut auditor_off(), &ready(graph.build()), 0)
|
||||
.record
|
||||
.body;
|
||||
let tainted: Vec<(&str, &str)> = body
|
||||
.taint
|
||||
.iter()
|
||||
.map(|row| (row.name.as_deref().unwrap_or("?"), row.reason))
|
||||
.collect();
|
||||
|
||||
assert!(
|
||||
tainted.contains(&("null-sink", "tainted-upstream")),
|
||||
"the sink is not a candidate but its taint is what explains the row: {tainted:?}"
|
||||
);
|
||||
let call_name = owned_name("peerspeak-call", 200);
|
||||
assert!(tainted.contains(&(call_name.as_str(), "peerspeak-owned")));
|
||||
}
|
||||
|
||||
/// A record must serialise to a single line. Newlines inside a JSON Lines
|
||||
/// record would split one record into two unparseable ones — and node names come
|
||||
/// from PipeWire properties, which are attacker-adjacent free text.
|
||||
#[test]
|
||||
fn a_record_serialises_to_exactly_one_line() {
|
||||
let mut graph = Graph::new();
|
||||
graph.app_node("evil\nname\r\nwith breaks", MediaRole::StreamOutput, 100);
|
||||
let projection = ready(graph.build());
|
||||
|
||||
let outcome = observe(&mut auditor_off(), &projection, 0);
|
||||
let json = serde_json::to_string(&outcome.record).expect("a record must serialise");
|
||||
assert_eq!(json.lines().count(), 1, "record split across lines: {json}");
|
||||
assert!(
|
||||
json.contains(r"evil\nname"),
|
||||
"the name must survive escaped"
|
||||
);
|
||||
}
|
||||
|
||||
// ── O5 metrics ────────────────────────────────────────────────────────────
|
||||
|
||||
fn sample(kind: EventKind, at_us: u64, gap_us: u64, recompute_us: u64, emit_us: u64) -> Sample {
|
||||
Sample {
|
||||
at_us,
|
||||
gap_us,
|
||||
recompute_us,
|
||||
emit_us,
|
||||
kind,
|
||||
}
|
||||
}
|
||||
|
||||
/// Bucket bounds are exclusive upper bounds, so a value exactly on a bound lands
|
||||
/// in the next bucket up. Asserted because an off-by-one here silently shifts
|
||||
/// the whole distribution the O5 conclusion rests on.
|
||||
#[test]
|
||||
fn histogram_bounds_are_exclusive_upper_bounds() {
|
||||
let mut metrics = Metrics::default();
|
||||
for us in [0, 49, 50, 99_999, 100_000, 1_000_000] {
|
||||
metrics.record(sample(EventKind::Graph, 0, 1_000, us, 0));
|
||||
}
|
||||
let summary = metrics.summary();
|
||||
|
||||
assert_eq!(
|
||||
summary.recompute_distribution,
|
||||
vec![
|
||||
("<50us", 2), // 0 and 49
|
||||
("<100us", 1), // 50
|
||||
("<100ms", 1), // 99_999
|
||||
(">=100ms", 2), // 100_000 and 1_000_000
|
||||
]
|
||||
);
|
||||
assert_eq!(summary.recompute_max_us, 1_000_000);
|
||||
}
|
||||
|
||||
/// The maximum is exact, not bucketed. O5 asks for the maximum specifically, and
|
||||
/// ">= 100 ms" is not an answer to "how bad does it get?".
|
||||
#[test]
|
||||
fn the_maximum_is_exact_not_bucketed() {
|
||||
let mut metrics = Metrics::default();
|
||||
metrics.record(sample(EventKind::Graph, 0, 1_000, 137, 0));
|
||||
metrics.record(sample(EventKind::Graph, 0, 1_000, 4_211, 0));
|
||||
metrics.record(sample(EventKind::Graph, 0, 1_000, 90, 0));
|
||||
|
||||
let summary = metrics.summary();
|
||||
assert_eq!(summary.recompute_max_us, 4_211);
|
||||
assert_eq!(summary.recompute_mean_us, Some((137 + 4_211 + 90) / 3));
|
||||
}
|
||||
|
||||
/// Nearest-rank quantiles over the buckets.
|
||||
#[test]
|
||||
fn quantiles_use_nearest_rank_over_the_buckets() {
|
||||
let mut metrics = Metrics::default();
|
||||
// 99 fast samples and one very slow one: the tail must show up at p99 and
|
||||
// nowhere earlier, which is the whole reason for reporting p99 at all.
|
||||
for _ in 0..99 {
|
||||
metrics.record(sample(EventKind::Graph, 0, 1_000, 10, 0));
|
||||
}
|
||||
metrics.record(sample(EventKind::Graph, 0, 1_000, 200_000, 0));
|
||||
|
||||
let summary = metrics.summary();
|
||||
assert_eq!(summary.recompute_p50, Some("<50us"));
|
||||
assert_eq!(summary.recompute_p90, Some("<50us"));
|
||||
assert_eq!(summary.recompute_p99, Some("<50us"));
|
||||
assert_eq!(summary.recompute_max_us, 200_000);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn an_empty_histogram_reports_no_quantiles_and_no_rate() {
|
||||
let summary = Metrics::default().summary();
|
||||
assert_eq!(summary.recompute_p50, None);
|
||||
assert_eq!(summary.recompute_mean_us, None);
|
||||
assert_eq!(summary.graph_events_per_sec, None);
|
||||
assert_eq!(summary.busy_fraction, None);
|
||||
assert_eq!(summary.recompute_max_us, 0);
|
||||
assert!(summary.recompute_distribution.is_empty());
|
||||
}
|
||||
|
||||
/// Ticks are counted separately from graph events. Folding them in would inflate
|
||||
/// the measured event rate by a constant 4 Hz and hide the real graph churn —
|
||||
/// which is the number O5 is actually about.
|
||||
#[test]
|
||||
fn ticks_do_not_count_toward_the_graph_event_rate() {
|
||||
let mut metrics = Metrics::default();
|
||||
// Two graph events one second apart, with ticks in between.
|
||||
metrics.record(sample(EventKind::Graph, 0, 0, 100, 0));
|
||||
for i in 1..4 {
|
||||
metrics.record(sample(EventKind::Tick, i * 250_000, 250_000, 100, 0));
|
||||
}
|
||||
metrics.record(sample(EventKind::Graph, 1_000_000, 250_000, 100, 0));
|
||||
|
||||
let summary = metrics.summary();
|
||||
assert_eq!(summary.graph_events, 2);
|
||||
assert_eq!(summary.tick_events, 3);
|
||||
// Span runs to the last sample's completion: 1_000_000 + 100 µs.
|
||||
assert_eq!(summary.span_us, 1_000_100);
|
||||
assert_eq!(summary.graph_events_per_sec, Some(2.0));
|
||||
}
|
||||
|
||||
/// The queueing proxy: an event beginning within the threshold of the previous
|
||||
/// sample's completion was almost certainly already waiting. The first sample is
|
||||
/// never counted — it has no predecessor to have queued behind, and counting it
|
||||
/// would put a phantom backlog in every run.
|
||||
#[test]
|
||||
fn the_queueing_proxy_counts_back_to_back_events_only() {
|
||||
let mut metrics = Metrics::default();
|
||||
metrics.record(sample(EventKind::Graph, 0, 0, 100, 0));
|
||||
metrics.record(sample(EventKind::Graph, 100, QUEUE_THRESHOLD_US, 100, 0));
|
||||
metrics.record(sample(
|
||||
EventKind::Graph,
|
||||
200,
|
||||
QUEUE_THRESHOLD_US + 1,
|
||||
100,
|
||||
0,
|
||||
));
|
||||
metrics.record(sample(EventKind::Graph, 300, 0, 100, 0));
|
||||
|
||||
let summary = metrics.summary();
|
||||
assert_eq!(
|
||||
summary.queued_events, 2,
|
||||
"exactly the two within the threshold, never the first sample"
|
||||
);
|
||||
assert_eq!(summary.queue_threshold_us, QUEUE_THRESHOLD_US);
|
||||
}
|
||||
|
||||
/// Emission cost is tracked separately from recompute cost, and a suppressed
|
||||
/// record contributes neither an emitted-record count nor an emit sample —
|
||||
/// otherwise the logging distribution would be diluted by every tick that wrote
|
||||
/// nothing.
|
||||
#[test]
|
||||
fn emission_cost_is_tracked_separately_from_recompute() {
|
||||
let mut metrics = Metrics::default();
|
||||
metrics.record(sample(EventKind::Graph, 0, 0, 300, 80));
|
||||
metrics.record(sample(EventKind::Tick, 1_000, 900, 200, 0));
|
||||
metrics.record(sample(EventKind::Graph, 2_000, 900, 400, 120));
|
||||
|
||||
let summary = metrics.summary();
|
||||
assert_eq!(summary.emitted_records, 2);
|
||||
assert_eq!(summary.emit_max_us, 120);
|
||||
assert_eq!(summary.emit_mean_us, Some(100));
|
||||
assert_eq!(
|
||||
summary.emit_distribution,
|
||||
vec![("<100us", 1), ("<250us", 1)]
|
||||
);
|
||||
// Busy time is recompute *and* logging: 300+80+200+400+120.
|
||||
assert_eq!(summary.busy_us, 1_100);
|
||||
}
|
||||
|
||||
/// The busy fraction needs no inference, unlike the queueing proxy, so it is the
|
||||
/// number the O5 verdict should lean on.
|
||||
#[test]
|
||||
fn the_busy_fraction_is_the_share_of_wall_time_spent_working() {
|
||||
let mut metrics = Metrics::default();
|
||||
metrics.record(sample(EventKind::Graph, 0, 0, 100, 0));
|
||||
// Ends at 1_000_000 + 900 → a span of 1_000_900 µs with 1_000 µs of work.
|
||||
metrics.record(sample(EventKind::Graph, 1_000_000, 999_900, 900, 0));
|
||||
|
||||
let summary = metrics.summary();
|
||||
assert_eq!(summary.busy_us, 1_000);
|
||||
assert_eq!(summary.span_us, 1_000_900);
|
||||
assert_eq!(summary.busy_fraction, Some(0.001));
|
||||
}
|
||||
|
||||
/// Bucket labels and bounds must stay parallel, or the distribution mislabels
|
||||
/// itself — a silent failure that would misreport every O5 result.
|
||||
#[test]
|
||||
fn bucket_labels_cover_every_bound_plus_overflow() {
|
||||
assert_eq!(
|
||||
BUCKET_LABELS.len(),
|
||||
super::metrics::BUCKET_BOUNDS_US.len() + 1
|
||||
);
|
||||
}
|
||||
@@ -1,4 +1,6 @@
|
||||
pub mod aec;
|
||||
pub mod audio;
|
||||
pub mod audit;
|
||||
mod capture;
|
||||
mod observer;
|
||||
mod pipeline;
|
||||
@@ -76,6 +78,12 @@ pub async fn run(opts: HostOpts) -> Result<()> {
|
||||
|
||||
let cancel = signal::install_ctrl_c();
|
||||
|
||||
// Phase 5 dry-run audit, off unless `PIXELPASS_AUDIO_AUDIT=1`. Read-only:
|
||||
// it observes the graph and logs what phases 2–4 conclude, creating no
|
||||
// links. Bound to a name so the handle lives as long as the run — dropping
|
||||
// it stops the observer thread and flushes the final O5 summary.
|
||||
let _audio_audit = audit::run::spawn_if_enabled()?;
|
||||
|
||||
let endpoint = endpoint::bind(opts.relay.as_deref()).await?;
|
||||
|
||||
// Relay-only ticket: wait for the home relay to connect, then keep only
|
||||
|
||||
+688
-75
@@ -4,12 +4,15 @@
|
||||
//! callbacks into [`RegEvent`]s, and publishes the latest [`Projection`] for
|
||||
//! consumers running outside the PipeWire thread.
|
||||
|
||||
use super::classify::DeviceClaim;
|
||||
use super::{LinkEndpoints, NodeObservation, Projection, RegEvent, RegistryModel};
|
||||
use super::classify::{DeviceClaim, DeviceProps};
|
||||
use super::{
|
||||
EventKind, LinkEndpoints, NodeObservation, Outcome, Projection, RegEvent, RegistryModel,
|
||||
};
|
||||
use crate::host::audio::parse_object_serial;
|
||||
use crate::host::taint::snapshot::{
|
||||
ClientSnapshot, GlobalId, MediaRole, NodeProps, PortDirection, PortSnapshot, Serial,
|
||||
};
|
||||
use crate::host::taint::{PEERSPEAK_OWNED_PROP, PEERSPEAK_OWNED_VALUE};
|
||||
use anyhow::{Context, Result};
|
||||
use pipewire::{self as pw, types::ObjectType};
|
||||
use std::cell::{Cell, RefCell};
|
||||
@@ -22,6 +25,27 @@ use std::time::{Duration, Instant};
|
||||
const READINESS_TIMEOUT_MILLIS: u64 = 2_000;
|
||||
const TICK_INTERVAL: Duration = Duration::from_millis(250);
|
||||
|
||||
/// A consumer that sees **every** projection, one per applied registry event,
|
||||
/// on the observer thread.
|
||||
///
|
||||
/// This exists because polling [`RegistryObserverHandle::latest`] coalesces, and
|
||||
/// some consumers cannot tolerate that. Phase 4's AEC validator is the concrete
|
||||
/// case: it detects a module unload by observing the *empty gap* before the next
|
||||
/// module appears, and PipeWire reuses module indices verbatim across an
|
||||
/// unload/reload (v3.4 §5.2 correction 3), so a consumer that misses the gap
|
||||
/// silently aliases a fresh module onto a dead module's validated identity.
|
||||
///
|
||||
/// **Implementations run inline on the PipeWire loop thread.** Whatever they do
|
||||
/// delays the next registry callback, so they must be bounded and must not
|
||||
/// block. The phase-5 audit is the only implementor and measures its own cost
|
||||
/// for exactly this reason.
|
||||
pub trait ProjectionSink: Send {
|
||||
/// `now_us` is monotonic microseconds since the observer started — the same
|
||||
/// clock that drives [`RegEvent::Tick`], so a sink's notion of time cannot
|
||||
/// drift from the readiness epoch's.
|
||||
fn on_projection(&mut self, projection: &Projection, kind: EventKind, now_us: u64);
|
||||
}
|
||||
|
||||
/// Tokio-side access to the observer's most recent coherent projection.
|
||||
pub struct RegistryObserverHandle {
|
||||
latest: Arc<Mutex<Option<Projection>>>,
|
||||
@@ -32,13 +56,22 @@ pub struct RegistryObserverHandle {
|
||||
impl RegistryObserverHandle {
|
||||
/// Spawn the read-only PipeWire registry observer.
|
||||
pub fn spawn() -> Result<Self> {
|
||||
Self::spawn_with_sink(None)
|
||||
}
|
||||
|
||||
/// Spawn the observer with a per-event [`ProjectionSink`] attached.
|
||||
///
|
||||
/// The sink is moved onto the observer thread and dropped when that thread
|
||||
/// exits, which is what lets a sink emit a final summary on shutdown without
|
||||
/// the caller arranging one.
|
||||
pub fn spawn_with_sink(sink: Option<Box<dyn ProjectionSink>>) -> Result<Self> {
|
||||
let latest = Arc::new(Mutex::new(None));
|
||||
let latest_for_thread = Arc::clone(&latest);
|
||||
let (shutdown_tx, shutdown_rx) = pw::channel::channel::<()>();
|
||||
let thread = std::thread::Builder::new()
|
||||
.name("pixelpass-pw-observer".to_string())
|
||||
.spawn(move || {
|
||||
if let Err(e) = run_observer(latest_for_thread, shutdown_rx) {
|
||||
if let Err(e) = run_observer(latest_for_thread, shutdown_rx, sink) {
|
||||
tracing::warn!(
|
||||
"registry observer: libpipewire thread exited with error: {e:#}"
|
||||
);
|
||||
@@ -74,14 +107,24 @@ impl Drop for RegistryObserverHandle {
|
||||
}
|
||||
}
|
||||
|
||||
struct BoundLink {
|
||||
_proxy: pw::link::Link,
|
||||
_listener: pw::link::LinkListener,
|
||||
enum BoundProxy {
|
||||
Node {
|
||||
_listener: pw::node::NodeListener,
|
||||
_proxy: pw::node::Node,
|
||||
},
|
||||
Device {
|
||||
_listener: pw::device::DeviceListener,
|
||||
_proxy: pw::device::Device,
|
||||
},
|
||||
Link {
|
||||
_listener: pw::link::LinkListener,
|
||||
_proxy: pw::link::Link,
|
||||
},
|
||||
}
|
||||
|
||||
#[derive(Default)]
|
||||
struct LiveGlobal {
|
||||
bound_link: Option<BoundLink>,
|
||||
serial: Serial,
|
||||
bound_proxy: Option<BoundProxy>,
|
||||
}
|
||||
|
||||
struct ObserverState {
|
||||
@@ -89,20 +132,36 @@ struct ObserverState {
|
||||
latest: Arc<Mutex<Option<Projection>>>,
|
||||
last_candidate: Option<u32>,
|
||||
live_globals: BTreeMap<GlobalId, VecDeque<LiveGlobal>>,
|
||||
sink: Option<Box<dyn ProjectionSink>>,
|
||||
started_at: Instant,
|
||||
}
|
||||
|
||||
impl ObserverState {
|
||||
fn new(latest: Arc<Mutex<Option<Projection>>>) -> Self {
|
||||
/// `started_at` is the observer's single time origin, shared with the
|
||||
/// readiness tick timer — so a sink's `now_us` and a `RegEvent::Tick`'s
|
||||
/// `now` are the same clock, not two that drift.
|
||||
fn new(
|
||||
latest: Arc<Mutex<Option<Projection>>>,
|
||||
sink: Option<Box<dyn ProjectionSink>>,
|
||||
started_at: Instant,
|
||||
) -> Self {
|
||||
Self {
|
||||
model: RegistryModel::new(0, READINESS_TIMEOUT_MILLIS),
|
||||
latest,
|
||||
last_candidate: None,
|
||||
live_globals: BTreeMap::new(),
|
||||
sink,
|
||||
started_at,
|
||||
}
|
||||
}
|
||||
|
||||
fn apply(&mut self, event: RegEvent) {
|
||||
self.model.apply(event);
|
||||
fn apply(&mut self, event: RegEvent) -> Outcome {
|
||||
// Taken before the model consumes the event: the sink is told what kind
|
||||
// of observation produced the projection, and deriving that from the
|
||||
// event itself is what stops the two from ever disagreeing.
|
||||
let kind = event.kind();
|
||||
let event_outcome = self.model.apply(event);
|
||||
let mut outcome = event_outcome;
|
||||
|
||||
let candidate = self.model.pulse_pid_candidate();
|
||||
if candidate != self.last_candidate {
|
||||
@@ -111,61 +170,107 @@ impl ObserverState {
|
||||
let comm = std::fs::read_to_string(format!("/proc/{pid}/comm"))
|
||||
.ok()
|
||||
.map(|comm| comm.trim_end_matches(['\r', '\n']).to_string());
|
||||
self.model.apply(RegEvent::ProcCommProbed { pid, comm });
|
||||
// Folded into the model directly rather than through `apply`, so
|
||||
// one registry event still yields exactly one sink call — the
|
||||
// no-coalescing contract cuts both ways, and a *duplicated*
|
||||
// observation would make the O5 event rate a fiction.
|
||||
if self.model.apply(RegEvent::ProcCommProbed { pid, comm }) == Outcome::Applied {
|
||||
outcome = Outcome::Applied;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
self.publish();
|
||||
// v3.5 §6.7 decision 2: a projection the model proved identical is not
|
||||
// published. Only the model can make that claim soundly, which is why
|
||||
// it is [`Outcome`] and not a diff of two snapshots here.
|
||||
if outcome == Outcome::Applied {
|
||||
self.publish(kind);
|
||||
}
|
||||
event_outcome
|
||||
}
|
||||
|
||||
fn publish(&self) {
|
||||
fn publish(&mut self, kind: EventKind) {
|
||||
let projection = self.model.project();
|
||||
if let Some(sink) = self.sink.as_mut() {
|
||||
let now_us = u64::try_from(self.started_at.elapsed().as_micros()).unwrap_or(u64::MAX);
|
||||
sink.on_projection(&projection, kind, now_us);
|
||||
}
|
||||
// Published after the sink has seen it, so the projection is moved
|
||||
// rather than cloned — the snapshot is the largest thing the observer
|
||||
// owns and this runs on every event.
|
||||
*self
|
||||
.latest
|
||||
.lock()
|
||||
.unwrap_or_else(|poisoned| poisoned.into_inner()) = Some(self.model.project());
|
||||
.unwrap_or_else(|poisoned| poisoned.into_inner()) = Some(projection);
|
||||
}
|
||||
|
||||
/// Record the global's id and apply its add event as one step, so the
|
||||
/// bound-link FIFO stays provably lockstep with the model's own `live_ids`
|
||||
/// bound-proxy FIFO stays provably lockstep with the model's own `live_ids`
|
||||
/// index. Recording only on *applied* adds (never on unknown object types
|
||||
/// or globals dropped for a missing serial) is what keeps the two id
|
||||
/// queues the same length per id — otherwise a phantom slot ahead of a
|
||||
/// bound Link would be popped on removal, leaking that Link's proxy.
|
||||
fn add(&mut self, id: GlobalId, event: RegEvent) {
|
||||
self.live_globals
|
||||
.entry(id)
|
||||
.or_default()
|
||||
.push_back(LiveGlobal::default());
|
||||
self.apply(event);
|
||||
/// queues the same length per id — otherwise a phantom slot could pop
|
||||
/// another generation's proxy after an id is recycled.
|
||||
fn add(&mut self, serial: Serial, id: GlobalId, event: RegEvent) {
|
||||
if self.apply(event) == Outcome::Applied {
|
||||
self.live_globals
|
||||
.entry(id)
|
||||
.or_default()
|
||||
.push_back(LiveGlobal {
|
||||
serial,
|
||||
bound_proxy: None,
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
fn attach_bound_link(&mut self, id: GlobalId, bound_link: BoundLink) {
|
||||
let Some(global) = self.live_globals.get_mut(&id).and_then(VecDeque::back_mut) else {
|
||||
/// Return a proxy that could not be attached so its listener is dropped
|
||||
/// after the caller releases the `RefCell` borrow.
|
||||
fn attach_bound_proxy(
|
||||
&mut self,
|
||||
id: GlobalId,
|
||||
serial: Serial,
|
||||
bound_proxy: BoundProxy,
|
||||
) -> Option<BoundProxy> {
|
||||
let Some(global) = self
|
||||
.live_globals
|
||||
.get_mut(&id)
|
||||
.and_then(|globals| globals.iter_mut().find(|global| global.serial == serial))
|
||||
else {
|
||||
tracing::warn!(
|
||||
global_id = id.0,
|
||||
"registry observer: link bind completed without a live global slot"
|
||||
serial = serial.0,
|
||||
"registry observer: bind completed without a live global slot"
|
||||
);
|
||||
return;
|
||||
return Some(bound_proxy);
|
||||
};
|
||||
global.bound_link = Some(bound_link);
|
||||
if global.bound_proxy.is_some() {
|
||||
tracing::warn!(
|
||||
global_id = id.0,
|
||||
serial = serial.0,
|
||||
"registry observer: live global slot already has a bound proxy"
|
||||
);
|
||||
return Some(bound_proxy);
|
||||
}
|
||||
global.bound_proxy = Some(bound_proxy);
|
||||
None
|
||||
}
|
||||
|
||||
fn remove_global(&mut self, id: GlobalId) -> Option<BoundLink> {
|
||||
let (bound_link, empty) = {
|
||||
fn remove_global(&mut self, id: GlobalId) -> Option<BoundProxy> {
|
||||
let (bound_proxy, empty) = {
|
||||
let globals = self.live_globals.get_mut(&id)?;
|
||||
let bound_link = globals.pop_front().and_then(|global| global.bound_link);
|
||||
(bound_link, globals.is_empty())
|
||||
let bound_proxy = globals.pop_front().and_then(|global| global.bound_proxy);
|
||||
(bound_proxy, globals.is_empty())
|
||||
};
|
||||
if empty {
|
||||
self.live_globals.remove(&id);
|
||||
}
|
||||
bound_link
|
||||
bound_proxy
|
||||
}
|
||||
}
|
||||
|
||||
fn run_observer(
|
||||
latest: Arc<Mutex<Option<Projection>>>,
|
||||
shutdown_rx: pw::channel::Receiver<()>,
|
||||
sink: Option<Box<dyn ProjectionSink>>,
|
||||
) -> Result<()> {
|
||||
let started_at = Instant::now();
|
||||
let main_loop =
|
||||
@@ -176,7 +281,7 @@ fn run_observer(
|
||||
.connect_rc(None)
|
||||
.context("pw core connect failed (is the daemon running?)")?;
|
||||
let registry = core.get_registry_rc().context("pw get_registry failed")?;
|
||||
let state = Rc::new(RefCell::new(ObserverState::new(latest)));
|
||||
let state = Rc::new(RefCell::new(ObserverState::new(latest, sink, started_at)));
|
||||
|
||||
let main_loop_for_shutdown = main_loop.clone();
|
||||
let _shutdown_receiver = shutdown_rx.attach(main_loop.loop_(), move |()| {
|
||||
@@ -215,6 +320,9 @@ fn run_observer(
|
||||
|
||||
match obj.type_ {
|
||||
ObjectType::Node => {
|
||||
// ⚠️ v3.5 §6.7: the global is an INDEX. Only `object.serial`
|
||||
// is read here; every property the engine reasons about
|
||||
// comes from the bind's `info` (phase 3r).
|
||||
let Some(props) = obj.props.as_ref() else {
|
||||
tracing::warn!(
|
||||
node_id = obj.id,
|
||||
@@ -226,41 +334,59 @@ fn run_observer(
|
||||
else {
|
||||
return;
|
||||
};
|
||||
let node_props = NodeProps {
|
||||
peerspeak_owned: truthy(props.get("peerspeak.owned")),
|
||||
pulse_module_id: props
|
||||
.get("pulse.module.id")
|
||||
.and_then(|value| value.parse::<u64>().ok()),
|
||||
link_group: props.get("node.link-group").map(str::to_owned),
|
||||
client_id: props
|
||||
.get("client.id")
|
||||
.and_then(|value| value.parse::<u32>().ok())
|
||||
.map(GlobalId),
|
||||
process_id: props
|
||||
.get("application.process.id")
|
||||
.and_then(|value| value.parse::<u32>().ok()),
|
||||
passthrough: truthy(props.get("node.passthrough")),
|
||||
session_device: false,
|
||||
};
|
||||
let observation = NodeObservation {
|
||||
state_for_global.borrow_mut().add(
|
||||
serial,
|
||||
id,
|
||||
name: props.get("node.name").map(str::to_owned),
|
||||
role: MediaRole::parse(props.get("media.class")),
|
||||
props: node_props,
|
||||
device_claim: DeviceClaim {
|
||||
device_id: props
|
||||
.get("device.id")
|
||||
.and_then(|value| value.parse::<u32>().ok())
|
||||
.map(GlobalId),
|
||||
device_api: props.get("device.api").map(str::to_owned),
|
||||
factory_name: props.get("factory.name").map(str::to_owned),
|
||||
alsa_driver_name: props.get("alsa.driver_name").map(str::to_owned),
|
||||
},
|
||||
RegEvent::NodeAdded { serial, id },
|
||||
);
|
||||
|
||||
let Some(registry) = registry_weak.upgrade() else {
|
||||
return;
|
||||
};
|
||||
state_for_global
|
||||
.borrow_mut()
|
||||
.add(id, RegEvent::NodeAdded(observation));
|
||||
let node: pw::node::Node = match registry.bind(obj) {
|
||||
Ok(node) => node,
|
||||
Err(e) => {
|
||||
tracing::warn!(
|
||||
node_id = obj.id,
|
||||
"registry observer: failed to bind Node for properties: {e}"
|
||||
);
|
||||
return;
|
||||
}
|
||||
};
|
||||
// This bit only recognizes the initial callback for the
|
||||
// change-mask fast path. Admission vs update remains
|
||||
// entirely the model's decision.
|
||||
let first_info = Cell::new(true);
|
||||
let state_for_info = Rc::downgrade(&state_for_global);
|
||||
let listener = node
|
||||
.add_listener_local()
|
||||
.info(move |info| {
|
||||
let Some(props) = info.props() else {
|
||||
return;
|
||||
};
|
||||
let first = first_info.replace(false);
|
||||
if !first
|
||||
&& !info.change_mask().contains(pw::node::NodeChangeMask::PROPS)
|
||||
{
|
||||
return;
|
||||
}
|
||||
if let Some(state) = state_for_info.upgrade() {
|
||||
state.borrow_mut().apply(RegEvent::NodeInfo {
|
||||
serial,
|
||||
observation: node_observation_from_props(props),
|
||||
});
|
||||
}
|
||||
})
|
||||
.register();
|
||||
let unattached = state_for_global.borrow_mut().attach_bound_proxy(
|
||||
id,
|
||||
serial,
|
||||
BoundProxy::Node {
|
||||
_listener: listener,
|
||||
_proxy: node,
|
||||
},
|
||||
);
|
||||
drop(unattached);
|
||||
}
|
||||
ObjectType::Port => {
|
||||
let Some(props) = obj.props.as_ref() else {
|
||||
@@ -299,6 +425,7 @@ fn run_observer(
|
||||
}
|
||||
};
|
||||
state_for_global.borrow_mut().add(
|
||||
serial,
|
||||
id,
|
||||
RegEvent::PortAdded(PortSnapshot {
|
||||
serial,
|
||||
@@ -323,6 +450,7 @@ fn run_observer(
|
||||
return;
|
||||
};
|
||||
state_for_global.borrow_mut().add(
|
||||
serial,
|
||||
id,
|
||||
RegEvent::ClientAdded(ClientSnapshot {
|
||||
serial,
|
||||
@@ -334,9 +462,72 @@ fn run_observer(
|
||||
);
|
||||
}
|
||||
ObjectType::Device => {
|
||||
state_for_global
|
||||
.borrow_mut()
|
||||
.add(id, RegEvent::DeviceAdded { id });
|
||||
// Index only, exactly as for a Node: `device.api` and
|
||||
// `alsa.driver_name` live on the bind's `info` (v3.5 §6.7
|
||||
// decision 4), not here.
|
||||
let Some(props) = obj.props.as_ref() else {
|
||||
tracing::warn!(
|
||||
device_id = obj.id,
|
||||
"registry observer: Device has no properties; dropping"
|
||||
);
|
||||
return;
|
||||
};
|
||||
let Some(serial) = parse_serial(obj.id, "Device", props.get("object.serial"))
|
||||
else {
|
||||
return;
|
||||
};
|
||||
state_for_global.borrow_mut().add(
|
||||
serial,
|
||||
id,
|
||||
RegEvent::DeviceAdded { serial, id },
|
||||
);
|
||||
|
||||
let Some(registry) = registry_weak.upgrade() else {
|
||||
return;
|
||||
};
|
||||
let device: pw::device::Device = match registry.bind(obj) {
|
||||
Ok(device) => device,
|
||||
Err(e) => {
|
||||
tracing::warn!(
|
||||
device_id = obj.id,
|
||||
"registry observer: failed to bind Device for properties: {e}"
|
||||
);
|
||||
return;
|
||||
}
|
||||
};
|
||||
let first_info = Cell::new(true);
|
||||
let state_for_info = Rc::downgrade(&state_for_global);
|
||||
let listener = device
|
||||
.add_listener_local()
|
||||
.info(move |info| {
|
||||
let Some(props) = info.props() else {
|
||||
return;
|
||||
};
|
||||
let first = first_info.replace(false);
|
||||
if !first
|
||||
&& !info
|
||||
.change_mask()
|
||||
.contains(pw::device::DeviceChangeMask::PROPS)
|
||||
{
|
||||
return;
|
||||
}
|
||||
if let Some(state) = state_for_info.upgrade() {
|
||||
state.borrow_mut().apply(RegEvent::DeviceInfo {
|
||||
serial,
|
||||
props: device_props_from_props(props),
|
||||
});
|
||||
}
|
||||
})
|
||||
.register();
|
||||
let unattached = state_for_global.borrow_mut().attach_bound_proxy(
|
||||
id,
|
||||
serial,
|
||||
BoundProxy::Device {
|
||||
_listener: listener,
|
||||
_proxy: device,
|
||||
},
|
||||
);
|
||||
drop(unattached);
|
||||
}
|
||||
ObjectType::Link => {
|
||||
let Some(props) = obj.props.as_ref() else {
|
||||
@@ -352,6 +543,7 @@ fn run_observer(
|
||||
};
|
||||
let endpoints = link_endpoints_from_props(props);
|
||||
state_for_global.borrow_mut().add(
|
||||
serial,
|
||||
id,
|
||||
RegEvent::LinkAdded {
|
||||
serial,
|
||||
@@ -398,24 +590,26 @@ fn run_observer(
|
||||
}
|
||||
})
|
||||
.register();
|
||||
state_for_global.borrow_mut().attach_bound_link(
|
||||
let unattached = state_for_global.borrow_mut().attach_bound_proxy(
|
||||
id,
|
||||
BoundLink {
|
||||
_proxy: link,
|
||||
serial,
|
||||
BoundProxy::Link {
|
||||
_listener: listener,
|
||||
_proxy: link,
|
||||
},
|
||||
);
|
||||
drop(unattached);
|
||||
}
|
||||
_ => {}
|
||||
}
|
||||
})
|
||||
.global_remove(move |id| {
|
||||
let id = GlobalId(id);
|
||||
let bound_link = state_for_remove.borrow_mut().remove_global(id);
|
||||
let bound_proxy = state_for_remove.borrow_mut().remove_global(id);
|
||||
state_for_remove
|
||||
.borrow_mut()
|
||||
.apply(RegEvent::Removed { id });
|
||||
drop(bound_link);
|
||||
drop(bound_proxy);
|
||||
})
|
||||
.register();
|
||||
|
||||
@@ -455,10 +649,77 @@ fn parse_serial(id: u32, kind: &str, raw: Option<&str>) -> Option<Serial> {
|
||||
}
|
||||
}
|
||||
|
||||
/// Lenient boolean for PipeWire's own `bool`-ish properties
|
||||
/// (`port.exclusive`, `port.monitor`, `node.passthrough`), whose spelling
|
||||
/// varies by producer. Leniency is the fail-closed direction *for these*:
|
||||
/// each one, when true, causes exclusion.
|
||||
fn truthy(value: Option<&str>) -> bool {
|
||||
value.is_some_and(|value| value != "false" && value != "0")
|
||||
}
|
||||
|
||||
/// The ownership carrier is matched **exactly**, not leniently (round 10,
|
||||
/// R10-4).
|
||||
///
|
||||
/// It is tempting to reuse [`truthy`] here on the grounds that treating an
|
||||
/// unexpected value as "owned" over-excludes and is therefore safe. That
|
||||
/// argument does not hold: leniency buys false-positive *exclusion*, not
|
||||
/// safety. Under `truthy`, `peerspeak.owned=""` and `peerspeak.owned=false `
|
||||
/// (trailing space) both mean owned, so any process can suppress a rival's
|
||||
/// audio from the share with a property it does not even have to spell right.
|
||||
///
|
||||
/// Fail-closed on this feature is about **ancestry** — an unresolvable graph
|
||||
/// is not eligible — not about parsing. The producer emits exactly
|
||||
/// [`PEERSPEAK_OWNED_VALUE`] at all three of its sites and is pinned to it by
|
||||
/// the shared cross-repo fixture, so there is no real value to be lenient
|
||||
/// about. And a missed tag is not silent: carrier 2 is a union with this one,
|
||||
/// so a garbled property still leaves the `node.name` prefix.
|
||||
fn peerspeak_owned(value: Option<&str>) -> bool {
|
||||
value == Some(PEERSPEAK_OWNED_VALUE)
|
||||
}
|
||||
|
||||
fn node_observation_from_props(props: &pw::spa::utils::dict::DictRef) -> NodeObservation {
|
||||
NodeObservation {
|
||||
name: props.get("node.name").map(str::to_string),
|
||||
role: MediaRole::parse(props.get("media.class")),
|
||||
props: NodeProps {
|
||||
// Carrier 1 only. Carrier 2 (the `node.name` prefix) is matched
|
||||
// in the engine off `NodeObservation::name` above, so each
|
||||
// carrier stays independently testable — see
|
||||
// [`crate::host::taint::PEERSPEAK_OWNED_NODE_PREFIX`].
|
||||
peerspeak_owned: peerspeak_owned(props.get(PEERSPEAK_OWNED_PROP)),
|
||||
pulse_module_id: props
|
||||
.get("pulse.module.id")
|
||||
.and_then(|value| value.parse::<u64>().ok()),
|
||||
link_group: props.get("node.link-group").map(str::to_string),
|
||||
client_id: props
|
||||
.get("client.id")
|
||||
.and_then(|value| value.parse::<u32>().ok())
|
||||
.map(GlobalId),
|
||||
process_id: props
|
||||
.get("application.process.id")
|
||||
.and_then(|value| value.parse::<u32>().ok()),
|
||||
passthrough: truthy(props.get("node.passthrough")),
|
||||
session_device: false,
|
||||
},
|
||||
device_claim: DeviceClaim {
|
||||
device_id: props
|
||||
.get("device.id")
|
||||
.and_then(|value| value.parse::<u32>().ok())
|
||||
.map(GlobalId),
|
||||
device_api: props.get("device.api").map(str::to_string),
|
||||
factory_name: props.get("factory.name").map(str::to_string),
|
||||
alsa_driver_name: props.get("alsa.driver_name").map(str::to_string),
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
fn device_props_from_props(props: &pw::spa::utils::dict::DictRef) -> DeviceProps {
|
||||
DeviceProps {
|
||||
device_api: props.get("device.api").map(str::to_string),
|
||||
alsa_driver_name: props.get("alsa.driver_name").map(str::to_string),
|
||||
}
|
||||
}
|
||||
|
||||
fn link_endpoints_from_props(props: &pw::spa::utils::dict::DictRef) -> Option<LinkEndpoints> {
|
||||
let output_node = props.get("link.output.node")?.parse::<u32>().ok()?;
|
||||
let input_node = props.get("link.input.node")?.parse::<u32>().ok()?;
|
||||
@@ -485,6 +746,165 @@ mod tests {
|
||||
use super::*;
|
||||
use std::process::Command;
|
||||
|
||||
/// **R10-4.** The ownership carrier is matched exactly; the lenient
|
||||
/// [`truthy`] spelling is wrong for it.
|
||||
///
|
||||
/// Under `truthy`, every value in `denied` below meant "peerspeak owns
|
||||
/// this" — including the empty string and a `false` with a trailing space
|
||||
/// — so any process could suppress a rival application's audio from the
|
||||
/// share with a property it did not have to spell correctly. Leniency here
|
||||
/// buys false-positive exclusion, not safety.
|
||||
#[test]
|
||||
fn the_ownership_carrier_is_matched_exactly_not_leniently() {
|
||||
assert!(peerspeak_owned(Some(PEERSPEAK_OWNED_VALUE)));
|
||||
|
||||
let denied = [
|
||||
None,
|
||||
Some(""),
|
||||
Some("false"),
|
||||
Some("0"),
|
||||
Some("false "),
|
||||
Some("true"),
|
||||
Some("yes"),
|
||||
Some("1 "),
|
||||
Some(" 1"),
|
||||
Some("01"),
|
||||
Some("2"),
|
||||
];
|
||||
for value in denied {
|
||||
assert!(
|
||||
!peerspeak_owned(value),
|
||||
"{value:?} must not read as peerspeak-owned"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
/// The same property, asserted through the **production wiring** rather
|
||||
/// than the helper.
|
||||
///
|
||||
/// ⚠️ **This is the gate; the one above is a unit test of a private
|
||||
/// function** (round 10 review, finding 4). Mutating
|
||||
/// [`node_observation_from_props`] back to `truthy(props.get(…))` left the
|
||||
/// helper test green, because it calls [`peerspeak_owned`] directly and
|
||||
/// the only live case it shares with production — exact `"1"` — passes
|
||||
/// under both implementations. That is precisely the "a gate satisfiable
|
||||
/// by two sources gates neither" failure that bit the `main.rs` wiring
|
||||
/// guard and phase 3r row 1.
|
||||
///
|
||||
/// So: build a real `pw_properties` dictionary, push it through the same
|
||||
/// function the registry callback calls, and assert the resulting
|
||||
/// [`NodeProps::peerspeak_owned`] for every spelling.
|
||||
#[test]
|
||||
fn the_production_wiring_reads_the_ownership_carrier_exactly() {
|
||||
pw::init();
|
||||
|
||||
// (property value, must be read as peerspeak-owned)
|
||||
let spellings = [
|
||||
(Some(PEERSPEAK_OWNED_VALUE), true),
|
||||
(None, false),
|
||||
(Some(""), false),
|
||||
(Some("false"), false),
|
||||
(Some("0"), false),
|
||||
(Some("false "), false),
|
||||
(Some("true"), false),
|
||||
(Some("yes"), false),
|
||||
(Some("1 "), false),
|
||||
(Some(" 1"), false),
|
||||
(Some("01"), false),
|
||||
(Some("2"), false),
|
||||
];
|
||||
|
||||
for (value, expected) in spellings {
|
||||
let mut props = pw::properties::PropertiesBox::new();
|
||||
// A realistic node, so the rest of the parse runs too: this is the
|
||||
// shape peerspeak's own tagged playback arrives in.
|
||||
props.insert("media.class", "Stream/Output/Audio");
|
||||
props.insert("node.name", "probe");
|
||||
props.insert("client.id", "42");
|
||||
if let Some(value) = value {
|
||||
props.insert(PEERSPEAK_OWNED_PROP, value);
|
||||
}
|
||||
|
||||
let observation = node_observation_from_props(props.dict());
|
||||
assert_eq!(
|
||||
observation.props.peerspeak_owned, expected,
|
||||
"{PEERSPEAK_OWNED_PROP}={value:?} through the real adapter"
|
||||
);
|
||||
// The surrounding parse must still work, or a green result above
|
||||
// could just mean the whole dictionary was dropped.
|
||||
assert_eq!(observation.role, MediaRole::StreamOutput);
|
||||
assert_eq!(observation.name.as_deref(), Some("probe"));
|
||||
assert_eq!(observation.props.client_id, Some(GlobalId(42)));
|
||||
}
|
||||
}
|
||||
|
||||
/// The cross-repo fixture's `prop_value` is the only spelling this
|
||||
/// consumer treats as owned — asserted through the production wiring.
|
||||
///
|
||||
/// The taint module's `ownership_carriers_match_the_cross_repo_fixture`
|
||||
/// proves the two repos agree on the *literal*. That is not the same as
|
||||
/// proving the shipping observer reads it, which is the half the round-10
|
||||
/// review's finding 6 was about: a future producer following the fixture
|
||||
/// needs the file to describe what the code does, and only a test that
|
||||
/// runs the code can keep those two honest.
|
||||
#[test]
|
||||
fn the_fixture_value_is_the_only_owned_spelling() {
|
||||
const FIXTURE: &str = include_str!("../../../tests/fixtures/ownership-tag-contract.txt");
|
||||
pw::init();
|
||||
|
||||
let pinned = FIXTURE
|
||||
.lines()
|
||||
.map(str::trim)
|
||||
.filter(|line| !line.is_empty() && !line.starts_with('#'))
|
||||
.map(|line| line.split_once('=').expect("fixture line is key=value"));
|
||||
let mut prop_key = None;
|
||||
let mut prop_value = None;
|
||||
for (key, value) in pinned {
|
||||
match key {
|
||||
"prop_key" => prop_key = Some(value),
|
||||
"prop_value" => prop_value = Some(value),
|
||||
_ => {}
|
||||
}
|
||||
}
|
||||
let prop_key = prop_key.expect("fixture defines prop_key");
|
||||
let prop_value = prop_value.expect("fixture defines prop_value");
|
||||
|
||||
let observe = |value: &str| {
|
||||
let mut props = pw::properties::PropertiesBox::new();
|
||||
props.insert("media.class", "Stream/Output/Audio");
|
||||
props.insert(prop_key, value);
|
||||
node_observation_from_props(props.dict())
|
||||
.props
|
||||
.peerspeak_owned
|
||||
};
|
||||
|
||||
assert!(
|
||||
observe(prop_value),
|
||||
"the fixture's own {prop_key}={prop_value} must read as owned"
|
||||
);
|
||||
// The spellings the fixture explicitly says are NOT owned.
|
||||
for denied in ["true", "yes", ""] {
|
||||
assert!(
|
||||
!observe(denied),
|
||||
"{prop_key}={denied:?} must not read as owned; the fixture says so"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
/// The other three boolean properties keep the lenient spelling, and that
|
||||
/// is deliberate rather than an oversight: each is PipeWire's own, each
|
||||
/// varies by producer, and each causes *exclusion* when true — so reading
|
||||
/// an unrecognised value as true is genuinely the safe direction for them.
|
||||
#[test]
|
||||
fn pipewires_own_boolean_props_stay_lenient() {
|
||||
assert!(truthy(Some("true")));
|
||||
assert!(truthy(Some("1")));
|
||||
assert!(truthy(Some("")));
|
||||
assert!(!truthy(Some("false")));
|
||||
assert!(!truthy(Some("0")));
|
||||
assert!(!truthy(None));
|
||||
}
|
||||
|
||||
struct PactlModule {
|
||||
id: Option<u32>,
|
||||
}
|
||||
@@ -559,6 +979,199 @@ mod tests {
|
||||
.any(|node| node.name.as_deref() == Some(name))
|
||||
}
|
||||
|
||||
/// Phase 3r exit-gate row 1, the Device half — and the reason it needs its
|
||||
/// own test.
|
||||
///
|
||||
/// `live_bound_properties_recover_node_and_device_inputs` asserts
|
||||
/// `session_device`, which the classifier grants on a **union**:
|
||||
/// `device.api` and `alsa.driver_name` may come from the bound Device *or*
|
||||
/// from the node's own copies. On this host (WirePlumber 0.5.15 ≥ 0.5.13)
|
||||
/// the session manager *does* copy both onto ALSA nodes, so that assertion
|
||||
/// passes through the node fallback and would keep passing if the Device
|
||||
/// bind delivered nothing at all — leaving v3.5 §6.7 decision 4, the whole
|
||||
/// authoritative path, ungated on the machine we develop on.
|
||||
///
|
||||
/// So assert the Device side directly: bind every Device global and require
|
||||
/// that at least one ALSA card announces **both** keys on its `info` props.
|
||||
/// A failure here means the fix for the phase-3 review's owed finding (a
|
||||
/// real card over-excluded on installs that do not copy `alsa.*` onto the
|
||||
/// node) rests on nothing.
|
||||
#[test]
|
||||
#[ignore = "needs live pipewire"]
|
||||
fn live_device_bind_carries_api_and_driver_name() {
|
||||
pw::init();
|
||||
let main_loop = pw::main_loop::MainLoopRc::new(None).expect("pw main loop");
|
||||
let context = pw::context::ContextRc::new(&main_loop, None).expect("pw context");
|
||||
let core = context.connect_rc(None).expect("pw core connect");
|
||||
let registry = core.get_registry_rc().expect("pw registry");
|
||||
|
||||
// Devices bound off the registry, each holding its proxy + listener so
|
||||
// the callback lives long enough to fire, exactly as the adapter does.
|
||||
let bound: Rc<RefCell<Vec<(pw::device::Device, pw::device::DeviceListener)>>> =
|
||||
Rc::new(RefCell::new(Vec::new()));
|
||||
let observed: Rc<RefCell<Vec<DeviceProps>>> = Rc::new(RefCell::new(Vec::new()));
|
||||
|
||||
let bound_for_global = Rc::clone(&bound);
|
||||
let observed_for_global = Rc::clone(&observed);
|
||||
let registry_weak = registry.downgrade();
|
||||
let _listener = registry
|
||||
.add_listener_local()
|
||||
.global(move |obj| {
|
||||
if obj.type_ != ObjectType::Device {
|
||||
return;
|
||||
}
|
||||
let Some(registry) = registry_weak.upgrade() else {
|
||||
return;
|
||||
};
|
||||
let Ok(device) = registry.bind::<pw::device::Device, _>(obj) else {
|
||||
return;
|
||||
};
|
||||
let observed_for_info = Rc::clone(&observed_for_global);
|
||||
let listener = device
|
||||
.add_listener_local()
|
||||
.info(move |info| {
|
||||
if let Some(props) = info.props() {
|
||||
observed_for_info
|
||||
.borrow_mut()
|
||||
.push(device_props_from_props(props));
|
||||
}
|
||||
})
|
||||
.register();
|
||||
bound_for_global.borrow_mut().push((device, listener));
|
||||
})
|
||||
.register();
|
||||
|
||||
// Two seconds is the same budget the observer gives its own binds.
|
||||
let main_loop_for_timer = main_loop.clone();
|
||||
let timer = main_loop
|
||||
.loop_()
|
||||
.add_timer(move |_| main_loop_for_timer.quit());
|
||||
timer
|
||||
.update_timer(Some(Duration::from_secs(2)), None)
|
||||
.into_result()
|
||||
.expect("arm the test deadline");
|
||||
main_loop.run();
|
||||
|
||||
let observed = observed.borrow();
|
||||
assert!(
|
||||
!observed.is_empty(),
|
||||
"no Device delivered info props at all — the Device bind path is dead"
|
||||
);
|
||||
assert!(
|
||||
observed.iter().any(|props| {
|
||||
props.device_api.as_deref() == Some("alsa") && props.alsa_driver_name.is_some()
|
||||
}),
|
||||
"no bound Device carried both device.api=alsa and alsa.driver_name; \
|
||||
observed: {observed:?}"
|
||||
);
|
||||
}
|
||||
|
||||
// Phase 3r exit-gate row 1: failure means the observation boundary regressed.
|
||||
#[test]
|
||||
#[ignore = "needs live pipewire"]
|
||||
fn live_bound_properties_recover_node_and_device_inputs() {
|
||||
pw::init();
|
||||
let observer = RegistryObserverHandle::spawn().expect("observer thread must spawn");
|
||||
wait_for(&observer, |projection| projection.graph_ready);
|
||||
|
||||
let unique = format!("pixelpass_observer_props_test_{}", std::process::id());
|
||||
let capture_name = format!("{unique}_capture");
|
||||
let playback_name = format!("{unique}_playback");
|
||||
let null_sink = PactlModule::load(
|
||||
"module-null-sink",
|
||||
&[
|
||||
format!("sink_name={unique}"),
|
||||
// The value peerspeak actually emits, not merely a truthy one:
|
||||
// this row is the live proof that carrier 1 survives the bind,
|
||||
// and the sink's name deliberately does *not* carry the
|
||||
// `peerspeak_owned_` prefix, so carrier 2 cannot stand in for
|
||||
// it here.
|
||||
format!(
|
||||
"sink_properties={PEERSPEAK_OWNED_PROP}={} node.passthrough=true",
|
||||
crate::host::taint::PEERSPEAK_OWNED_VALUE
|
||||
),
|
||||
],
|
||||
);
|
||||
let null_sink_id = null_sink.id.expect("null-sink module must have an id");
|
||||
let loopback = PactlModule::load(
|
||||
"module-loopback",
|
||||
&[
|
||||
format!("source={unique}.monitor"),
|
||||
format!("sink={unique}"),
|
||||
format!("source_output_properties=node.name={capture_name}"),
|
||||
format!("sink_input_properties=node.name={playback_name}"),
|
||||
],
|
||||
);
|
||||
|
||||
let projection = wait_for(&observer, |projection| {
|
||||
projection.graph_ready
|
||||
&& has_node(projection, &unique)
|
||||
&& has_node(projection, &capture_name)
|
||||
&& has_node(projection, &playback_name)
|
||||
});
|
||||
let tagged_sink = projection
|
||||
.snapshot
|
||||
.nodes()
|
||||
.find(|node| node.name.as_deref() == Some(&unique))
|
||||
.expect("tagged null sink must be projected");
|
||||
assert!(tagged_sink.props.peerspeak_owned);
|
||||
assert!(tagged_sink.props.passthrough);
|
||||
assert_eq!(
|
||||
tagged_sink.props.pulse_module_id,
|
||||
Some(u64::from(null_sink_id))
|
||||
);
|
||||
|
||||
let capture = projection
|
||||
.snapshot
|
||||
.nodes()
|
||||
.find(|node| node.name.as_deref() == Some(&capture_name))
|
||||
.expect("loopback capture leg must be projected");
|
||||
let playback = projection
|
||||
.snapshot
|
||||
.nodes()
|
||||
.find(|node| node.name.as_deref() == Some(&playback_name))
|
||||
.expect("loopback playback leg must be projected");
|
||||
let capture_group = capture
|
||||
.props
|
||||
.link_group
|
||||
.as_ref()
|
||||
.expect("loopback capture leg must carry node.link-group");
|
||||
let playback_group = playback
|
||||
.props
|
||||
.link_group
|
||||
.as_ref()
|
||||
.expect("loopback playback leg must carry node.link-group");
|
||||
assert_eq!(capture_group, playback_group);
|
||||
assert!(
|
||||
projection
|
||||
.snapshot
|
||||
.nodes()
|
||||
.any(|node| node.props.process_id.is_some()),
|
||||
"at least one projected node must carry application.process.id"
|
||||
);
|
||||
let session_device = projection.snapshot.nodes().find(|node| {
|
||||
node.props.session_device
|
||||
&& (node
|
||||
.name
|
||||
.as_deref()
|
||||
.is_some_and(|name| name.contains("alsa"))
|
||||
|| matches!(node.role, MediaRole::Sink | MediaRole::Source))
|
||||
});
|
||||
assert!(
|
||||
session_device.is_some(),
|
||||
"a named ALSA or Audio/Sink/Audio/Source node must classify as a session device"
|
||||
);
|
||||
assert!(projection.graph_ready);
|
||||
|
||||
loopback.unload();
|
||||
null_sink.unload();
|
||||
wait_for(&observer, |projection| {
|
||||
!has_node(projection, &unique)
|
||||
&& !has_node(projection, &capture_name)
|
||||
&& !has_node(projection, &playback_name)
|
||||
});
|
||||
}
|
||||
|
||||
#[test]
|
||||
#[ignore = "needs live pipewire"]
|
||||
fn live_topology_diff_tracks_null_sink_and_loopback() {
|
||||
|
||||
+104
-37
@@ -18,11 +18,21 @@
|
||||
//! both. So the discriminator is `factory.name` on an **allowlist** of
|
||||
//! real hardware-PCM factories, never a substring or a denylist: an unknown
|
||||
//! factory is not a device.
|
||||
//! - The backing Device must actually have been observed. A node that claims
|
||||
//! a `device.id` we have not yet resolved is **withheld**, not admitted with
|
||||
//! a provisional `false` — a provisional `false` during the not-ready
|
||||
//! window fuses sink and mic on the shared session client and that fusion
|
||||
//! can persist as sticky over-exclusion (round-3 finding 3).
|
||||
//! - The backing Device must actually have been **bound and resolved**. A node
|
||||
//! that claims a `device.id` whose Device's properties we do not hold is
|
||||
//! **withheld**, not admitted with a provisional `false` — a provisional
|
||||
//! `false` during the not-ready window fuses sink and mic on the shared
|
||||
//! session client and that fusion can persist as sticky over-exclusion
|
||||
//! (round-3 finding 3).
|
||||
//!
|
||||
//! **Round 8 (v3.5 §6.7 decision 4): the Device is the authority on
|
||||
//! `device.api` and `alsa.driver_name`.** Both are absent from the Node
|
||||
//! *global* and both are present on the **bound Device**'s `info` props
|
||||
//! (measured 2026-07-25). Reading them from the Device closes the phase-3
|
||||
//! review's owed fix: on PipeWire ≥ 1.2.6 with WirePlumber < 0.5.13 the driver
|
||||
//! name is not copied onto the node, and the fail-closed "absent driver ⇒ not
|
||||
//! a session device" rule would over-exclude real sound cards. `factory.name`
|
||||
//! exists only on the node, which is why the node bind is required regardless.
|
||||
|
||||
use crate::host::taint::snapshot::GlobalId;
|
||||
|
||||
@@ -54,6 +64,11 @@ const HARDWARE_PCM_FACTORIES: &[&str] = &[
|
||||
"api.alsa.pcm.source",
|
||||
];
|
||||
|
||||
/// The `device.api` every entry in [`HARDWARE_PCM_FACTORIES`] belongs to.
|
||||
/// A single value rather than a list, because the allowlist is ALSA-only;
|
||||
/// this constant is the thing to change when that stops being true.
|
||||
const HARDWARE_PCM_API: &str = "alsa";
|
||||
|
||||
/// ALSA drivers that expose a hardware-PCM `factory.name` but are **not**
|
||||
/// passive terminals — audio written in reappears on their capture side
|
||||
/// through a path the PipeWire Link graph cannot see, so classifying them
|
||||
@@ -67,8 +82,9 @@ const HARDWARE_PCM_FACTORIES: &[&str] = &[
|
||||
/// does not couple playback to capture, so it is not a loopback hazard.
|
||||
const NON_TERMINAL_ALSA_DRIVERS: &[&str] = &["snd_aloop"];
|
||||
|
||||
/// The three node properties the classifier reads, exactly as the adapter
|
||||
/// parsed them off the Node global. Kept separate from
|
||||
/// The node-side properties the classifier reads, exactly as the adapter
|
||||
/// parsed them off the **bound Node's `info`** (never off the registry
|
||||
/// global — v3.5 §6.7). Kept separate from
|
||||
/// [`super::super::taint::snapshot::NodeProps`] because these feed the
|
||||
/// *decision* whose output is the `session_device` field — they are inputs,
|
||||
/// not part of the graph the engine reasons over.
|
||||
@@ -78,10 +94,12 @@ pub struct DeviceClaim {
|
||||
/// `Stream/*` nodes, which is exactly why their absence means "not a
|
||||
/// device", not "unknown".
|
||||
pub device_id: Option<GlobalId>,
|
||||
/// `device.api` — the access API of that Device (e.g. `alsa`, `bluez5`).
|
||||
/// Its mere presence is **not** sufficient (a card-associated filter has
|
||||
/// it too); required only as a corroborating signal alongside the factory
|
||||
/// allowlist.
|
||||
/// `device.api` **as copied onto the node**, when it is — the access API
|
||||
/// of that Device (e.g. `alsa`, `bluez5`). Its mere presence is **not**
|
||||
/// sufficient (a card-associated filter has it too); required only as a
|
||||
/// corroborating signal alongside the factory allowlist. The
|
||||
/// authoritative copy is [`DeviceProps::device_api`]; this is the
|
||||
/// fallback.
|
||||
pub device_api: Option<String>,
|
||||
/// `factory.name` — the discriminator. Only an allowlisted hardware-PCM
|
||||
/// factory earns `session_device`.
|
||||
@@ -92,8 +110,27 @@ pub struct DeviceClaim {
|
||||
/// shares the same factory. `session_device` requires this to be
|
||||
/// **present and not** on [`NON_TERMINAL_ALSA_DRIVERS`]; a driver on the
|
||||
/// denylist, or an absent value, both fail closed (see [`classify`]).
|
||||
/// May be absent on non-ALSA backends or on version pairings that do not
|
||||
/// copy `alsa.*` onto the node.
|
||||
/// Frequently absent here — PipeWire ≥ 1.2.6 with WirePlumber < 0.5.13
|
||||
/// does not copy `alsa.*` onto the node — which is why the authoritative
|
||||
/// copy is [`DeviceProps::alsa_driver_name`] and this is only the
|
||||
/// fallback.
|
||||
pub alsa_driver_name: Option<String>,
|
||||
}
|
||||
|
||||
/// The **bound Device's** `info` properties — the authoritative half of the
|
||||
/// `session_device` decision (v3.5 §6.7 decision 4).
|
||||
///
|
||||
/// Absent from the Device *registry global* exactly as the node's properties
|
||||
/// are absent from the Node global; both are recovered by binding. A node
|
||||
/// claiming a `device.id` is withheld until this struct exists for that
|
||||
/// Device (see [`Classification::Withhold`]).
|
||||
#[derive(Clone, Debug, Default, PartialEq, Eq)]
|
||||
pub struct DeviceProps {
|
||||
/// `device.api` on the Device — `alsa`, `bluez5`, `v4l2`, …
|
||||
pub device_api: Option<String>,
|
||||
/// `alsa.driver_name` on the Device — the kernel driver behind the card,
|
||||
/// authoritative regardless of whether the session manager copied it onto
|
||||
/// the node.
|
||||
pub alsa_driver_name: Option<String>,
|
||||
}
|
||||
|
||||
@@ -102,9 +139,10 @@ pub struct DeviceClaim {
|
||||
pub enum Classification {
|
||||
/// No `device.id` — a `Stream/*` node. Admit with `session_device=false`.
|
||||
NotADevice,
|
||||
/// A `device.id` is claimed but the backing Device has not been resolved
|
||||
/// yet. **Withhold the node and keep the readiness epoch not-ready**;
|
||||
/// re-classify when the Device is observed.
|
||||
/// A `device.id` is claimed but the backing Device's properties are not
|
||||
/// held: never observed, its bind still outstanding, or its global id
|
||||
/// ambiguously shared by two live Devices. **Withhold the node and keep
|
||||
/// the readiness epoch not-ready**; re-classify when the Device resolves.
|
||||
Withhold { device_id: GlobalId },
|
||||
/// Positively a passive hardware terminal. Admit with
|
||||
/// `session_device=true`.
|
||||
@@ -115,42 +153,71 @@ pub enum Classification {
|
||||
NotSessionDevice,
|
||||
}
|
||||
|
||||
/// Classify a node's device claim.
|
||||
/// Classify a node's device claim against its backing Device.
|
||||
///
|
||||
/// `device_resolved` is whether [`DeviceClaim::device_id`] has been observed
|
||||
/// as a Device global; it is only consulted when a `device_id` is present.
|
||||
/// Pure: the model supplies `device_resolved` from its resolved-Device set,
|
||||
/// and the I/O of *binding* the Device lives in the adapter.
|
||||
pub fn classify(claim: &DeviceClaim, device_resolved: bool) -> Classification {
|
||||
/// `device` is the bound Device's properties, and `None` means the claim is
|
||||
/// **unresolved** — never observed, bind outstanding, or an ambiguous
|
||||
/// recycled id. It is only consulted when a `device_id` is present. Pure: the
|
||||
/// model looks the Device up, and the I/O of *binding* it lives in the
|
||||
/// adapter.
|
||||
///
|
||||
/// Where the two sides disagree the rule is deliberately asymmetric, and
|
||||
/// safety picks the direction (v3.5 §6.7 decision 4):
|
||||
///
|
||||
/// - **Presence: the Device wins, the node is the fallback.** That is what
|
||||
/// recovers a real card whose node was never given `alsa.driver_name`.
|
||||
/// - **The denylist is a union.** If *either* side names a non-terminal
|
||||
/// driver the node is not a session device. A disagreement here is not
|
||||
/// expected on any measured configuration, and treating it as "the Device
|
||||
/// says it is fine" would be the one reading that can leak.
|
||||
pub fn classify(claim: &DeviceClaim, device: Option<&DeviceProps>) -> Classification {
|
||||
let Some(device_id) = claim.device_id else {
|
||||
// No backing Device: a stream. Not withheld, not a device.
|
||||
return Classification::NotADevice;
|
||||
};
|
||||
if !device_resolved {
|
||||
// Backed by a Device we have not seen — the one case that blocks
|
||||
let Some(device) = device else {
|
||||
// Backed by a Device we have not resolved — the one case that blocks
|
||||
// readiness. A provisional answer here is the leak the contract
|
||||
// forbids.
|
||||
return Classification::Withhold { device_id };
|
||||
}
|
||||
};
|
||||
let on_factory_allowlist = claim
|
||||
.factory_name
|
||||
.as_deref()
|
||||
.is_some_and(|f| HARDWARE_PCM_FACTORIES.contains(&f));
|
||||
// A **present, non-denied** ALSA driver is required — absence fails closed
|
||||
// (Codex phase-3 re-review). `alsa.driver_name` is not copied onto the
|
||||
// node on every PipeWire/WirePlumber version pairing (PipeWire ≥1.2.6
|
||||
// stopped overwriting node props with card props; WirePlumber only began
|
||||
// copying `alsa.*` onto nodes in 0.5.13), so a *missing* value must not be
|
||||
// read as "not a loopback" — that is exactly the hole an `snd_aloop` node
|
||||
// without the property would slip through. A real card whose node lacks
|
||||
// the driver is instead over-excluded (keeps its owner keys — safe);
|
||||
// recovering `session_device` for it needs reading the driver from the
|
||||
// backing Device global, which is owed to a later round.
|
||||
let driver_ok = claim
|
||||
// (Codex phase-3 re-review). The factory allowlist cannot tell a real card
|
||||
// from `snd_aloop`, which presents the same `api.alsa.pcm.*` factory, so a
|
||||
// *missing* value must not be read as "not a loopback". Round 8 makes the
|
||||
// bound Device the primary source, so a real card is no longer
|
||||
// over-excluded merely because the session manager did not copy `alsa.*`
|
||||
// onto its node.
|
||||
let driver = device
|
||||
.alsa_driver_name
|
||||
.as_deref()
|
||||
.is_some_and(|d| !NON_TERMINAL_ALSA_DRIVERS.contains(&d));
|
||||
let is_hardware_pcm = claim.device_api.is_some() && on_factory_allowlist && driver_ok;
|
||||
.or(claim.alsa_driver_name.as_deref());
|
||||
let driver_denied = [
|
||||
device.alsa_driver_name.as_deref(),
|
||||
claim.alsa_driver_name.as_deref(),
|
||||
]
|
||||
.into_iter()
|
||||
.flatten()
|
||||
.any(|d| NON_TERMINAL_ALSA_DRIVERS.contains(&d));
|
||||
let driver_ok = driver.is_some() && !driver_denied;
|
||||
// The API must positively be the one the factory allowlist is written
|
||||
// for, not merely present (Codex phase-3r review, finding 3). "Present"
|
||||
// admitted `device.api=v4l2` alongside `factory.name=api.alsa.pcm.sink`
|
||||
// — a contradiction no truthful configuration produces, which is exactly
|
||||
// why it should be read as an observation gone wrong rather than as
|
||||
// corroboration. Disagreement between the two sides fails closed for the
|
||||
// same reason. ⚠️ Tied to [`HARDWARE_PCM_FACTORIES`] being ALSA-only:
|
||||
// adding a BlueZ factory means allowing `bluez5` here too.
|
||||
let api_ok = match (device.device_api.as_deref(), claim.device_api.as_deref()) {
|
||||
(Some(from_device), Some(from_node)) if from_device != from_node => false,
|
||||
(Some(api), _) | (None, Some(api)) => api == HARDWARE_PCM_API,
|
||||
(None, None) => false,
|
||||
};
|
||||
let is_hardware_pcm = api_ok && on_factory_allowlist && driver_ok;
|
||||
if is_hardware_pcm {
|
||||
Classification::SessionDevice
|
||||
} else {
|
||||
|
||||
+374
-126
@@ -1,12 +1,34 @@
|
||||
//! The registry observer's **pure core** (impl plan §4, phase 3).
|
||||
//! The registry observer's **pure core** (impl plan §4, phases 3 and 3r).
|
||||
//!
|
||||
//! This is my half of the phase-3 split: a reducer that folds a stream of
|
||||
//! typed [`RegEvent`]s into a live model of the PipeWire graph and projects
|
||||
//! the [`GraphSnapshot`] + context the taint engine (phase 2) consumes. **No
|
||||
//! PipeWire types appear here** — the I/O adapter (Codex's half) translates
|
||||
//! live registry callbacks, Link/Device binds, `/proc` reads, and the
|
||||
//! `core.sync`/`done` round-trip into these events and feeds them in. Every
|
||||
//! test in this module builds the event stream by hand.
|
||||
//! live registry callbacks, binds, `/proc` reads, and the `core.sync`/`done`
|
||||
//! round-trip into these events and feeds them in. Every test in this module
|
||||
//! builds the event stream by hand.
|
||||
//!
|
||||
//! ## 🔴 Round 8 (v3.5 §6.7): the global is an INDEX, not a source of truth
|
||||
//!
|
||||
//! Phase 3 shipped reading node properties off the registry `global` event.
|
||||
//! The registry announces only a fixed 13-key subset for a Node, and **eight
|
||||
//! properties this feature depends on are never among them** — they read as
|
||||
//! absent rather than failing, so the engine was silently, permanently
|
||||
//! starved of both its primary taint root and every strong owner key (the
|
||||
//! phase-5 gate failure, F1/F2). The rule that replaces it:
|
||||
//!
|
||||
//! > A node's properties come from a **bind**, never from the global. The
|
||||
//! > global tells us an object exists, its id and its serial. Everything
|
||||
//! > else — including `node.name` and `media.class`, so there is exactly one
|
||||
//! > source — arrives on [`RegEvent::NodeInfo`]. Same for `Device`
|
||||
//! > ([`RegEvent::DeviceInfo`]).
|
||||
//!
|
||||
//! Consequences visible in this file: a Node is admitted to the snapshot
|
||||
//! **only** once its `info` has arrived (until then it is withheld and is a
|
||||
//! readiness obligation); a Device resolves a node's claim only once *its*
|
||||
//! `info` has arrived; and `info` may fire again for the lifetime of the
|
||||
//! object, so [`RegEvent::NodeInfo`] is both the first resolution and every
|
||||
//! later property change (v3.5 §6.7 decisions 1–4).
|
||||
//!
|
||||
//! Three things this core is shaped to get right, each an exit-gate row:
|
||||
//!
|
||||
@@ -14,18 +36,20 @@
|
||||
//! id, and those recycle. The model keeps an insertion-ordered index per id
|
||||
//! so a removal accounts for the *oldest* generation first, and the
|
||||
//! snapshot projection treats any id still claimed by two live objects as
|
||||
//! [`IdLookup::Ambiguous`] — fail closed (v3.4 §6.1.3).
|
||||
//! [`IdLookup::Ambiguous`] — fail closed (v3.4 §6.1.3). Everything the
|
||||
//! model *owns* is keyed by never-recycled `object.serial`; ids are only
|
||||
//! ever a lookup.
|
||||
//! - **The readiness epoch.** `graph_ready` is false until the initial graph
|
||||
//! is fully observed: the server has synced **and** no binds/withheld nodes
|
||||
//! remain outstanding. A bounded timeout makes it fail closed. It gates
|
||||
//! sticky *retirement* only; withholding after completion is per-object.
|
||||
//! - **Withholding on unresolved devices.** A node claiming a `device.id`
|
||||
//! whose Device we have not observed is held out of the snapshot entirely
|
||||
//! rather than admitted with a provisional `session_device` (see
|
||||
//! [`classify`]).
|
||||
//! - **Withholding on unresolved input.** A node with no `info` yet, or one
|
||||
//! claiming a `device.id` whose Device we have not resolved, is held out of
|
||||
//! the snapshot entirely rather than admitted with provisional ownership
|
||||
//! (see [`classify`]).
|
||||
//!
|
||||
//! **Two accepted limitations (Codex phase-3 review, findings 3 and 4), both
|
||||
//! low-reachability, owed to a later hardening round:**
|
||||
//! **Three accepted limitations, all low-reachability, owed to a later
|
||||
//! hardening round:**
|
||||
//!
|
||||
//! - *A Link dropped for a missing `object.serial`/props is unrepresented.*
|
||||
//! The adapter drops such a global before it reaches [`RegistryModel`], so
|
||||
@@ -45,6 +69,13 @@
|
||||
//! silently drop `global_remove`, so this needs callback loss to trigger.
|
||||
//! The snapshot treats the two-claimant window as [`IdLookup::Ambiguous`]
|
||||
//! (fail closed) meanwhile.
|
||||
//! - *An unresolvable bind takes the whole graph down, not just its node*
|
||||
//! (v3.5 §6.7 decision 3). A node whose `info` never arrives keeps
|
||||
//! readiness false until the deadline, then sticky-[`Readiness::TimedOut`]
|
||||
//! — no fan-out at all, identical to a never-resolving Link bind. Per-node
|
||||
//! quarantine (that node ineligible **and** taint-bearing, the rest of the
|
||||
//! graph still working) is strictly better and is deferred because it is a
|
||||
//! new concept in the *pure engine*, not a fix to the observer.
|
||||
|
||||
#![allow(dead_code)] // Wired by the phase-3 adapter (Codex's half) and consumed by later phases.
|
||||
|
||||
@@ -59,7 +90,7 @@ use crate::host::taint::snapshot::{
|
||||
ClientSnapshot, GlobalId, GraphSnapshot, LinkSnapshot, MediaRole, NodeProps, NodeSnapshot,
|
||||
PortSnapshot, Serial,
|
||||
};
|
||||
use classify::{Classification, DeviceClaim};
|
||||
use classify::{Classification, DeviceClaim, DeviceProps};
|
||||
use std::collections::{BTreeMap, VecDeque};
|
||||
|
||||
/// A monotonic millisecond clock value, supplied by the adapter via
|
||||
@@ -67,14 +98,17 @@ use std::collections::{BTreeMap, VecDeque};
|
||||
/// [`std::time::Instant`] so the readiness timeout is deterministic in tests.
|
||||
pub type Millis = u64;
|
||||
|
||||
/// A Node as observed off the registry, before `session_device` has been
|
||||
/// decided. The adapter fills [`NodeProps`] with everything it can parse and
|
||||
/// leaves `session_device` at its `false` default; the model overwrites it
|
||||
/// from the [`classify`] result once the backing Device (if any) is resolved.
|
||||
/// A Node's **bound `info` properties** — the sole source of node properties
|
||||
/// (v3.5 §6.7), delivered by [`RegEvent::NodeInfo`].
|
||||
///
|
||||
/// This carries no identity: the serial names the node on the event and the
|
||||
/// global id was recorded by [`RegEvent::NodeAdded`], so the adapter cannot
|
||||
/// contradict the index it already published. `session_device` inside
|
||||
/// [`NodeObservation::props`] is left at its `false` default; the model
|
||||
/// overwrites it from the [`classify`] result at projection time, once the
|
||||
/// backing Device (if any) is resolved.
|
||||
#[derive(Clone, Debug, PartialEq, Eq)]
|
||||
pub struct NodeObservation {
|
||||
pub serial: Serial,
|
||||
pub id: GlobalId,
|
||||
pub name: Option<String>,
|
||||
pub role: MediaRole,
|
||||
pub props: NodeProps,
|
||||
@@ -97,19 +131,39 @@ pub struct LinkEndpoints {
|
||||
/// model consumes them in [`RegistryModel::apply`].
|
||||
#[derive(Clone, Debug, PartialEq, Eq)]
|
||||
pub enum RegEvent {
|
||||
/// A Node global appeared. Admitted immediately unless it claims an
|
||||
/// unresolved Device (then withheld — see [`classify`]).
|
||||
NodeAdded(NodeObservation),
|
||||
/// A Node global appeared. **Index only** — the global's properties are a
|
||||
/// filtered subset and are not read (v3.5 §6.7). The node is withheld
|
||||
/// from the snapshot and is a readiness obligation until its
|
||||
/// [`RegEvent::NodeInfo`] arrives.
|
||||
NodeAdded { serial: Serial, id: GlobalId },
|
||||
/// A bound Node's `info` properties. **Both** the first resolution and
|
||||
/// every later `PROPS` change for the node's lifetime — the model tells
|
||||
/// them apart, so the adapter holds no per-node "have I seen info yet?"
|
||||
/// state to get wrong. An `info` for a serial we do not hold (a node
|
||||
/// already removed) is ignored.
|
||||
NodeInfo {
|
||||
serial: Serial,
|
||||
observation: NodeObservation,
|
||||
},
|
||||
/// A Port global appeared.
|
||||
PortAdded(PortSnapshot),
|
||||
/// A Client global appeared. Feeds pulse-PID derivation via `sec_pid`.
|
||||
ClientAdded(ClientSnapshot),
|
||||
/// A Device global appeared. Resolves any nodes withheld on its id.
|
||||
DeviceAdded { id: GlobalId },
|
||||
/// A Device global appeared. Index only, exactly as for a Node: it does
|
||||
/// not resolve anything until [`RegEvent::DeviceInfo`] arrives.
|
||||
DeviceAdded { serial: Serial, id: GlobalId },
|
||||
/// A bound Device's `info` properties — the **authoritative** source of
|
||||
/// `device.api` and `alsa.driver_name` (v3.5 §6.7 decision 4). Resolves
|
||||
/// every node withheld on this Device's id.
|
||||
DeviceInfo { serial: Serial, props: DeviceProps },
|
||||
/// A Link global appeared. `endpoints` is `Some` when the global carried
|
||||
/// them (the optimisation) and `None` when the adapter must bind to learn
|
||||
/// them (the correctness path) — the latter is an outstanding obligation
|
||||
/// until a matching [`RegEvent::LinkEndpointsResolved`] arrives.
|
||||
///
|
||||
/// Unlike Nodes and Devices, Link endpoint props **are** announced on the
|
||||
/// global (measured, phase-5 results F1), so this asymmetry is real and
|
||||
/// deliberate.
|
||||
LinkAdded {
|
||||
serial: Serial,
|
||||
id: GlobalId,
|
||||
@@ -133,16 +187,75 @@ pub enum RegEvent {
|
||||
Tick { now: Millis },
|
||||
}
|
||||
|
||||
/// What kind of observation drove a projection.
|
||||
///
|
||||
/// Derived from the event itself ([`RegEvent::kind`]) rather than passed
|
||||
/// alongside it, so a consumer's view of "was this a real graph change?" cannot
|
||||
/// disagree with what the model was actually fed. The distinction matters to the
|
||||
/// phase-5 audit twice over: ticks arrive at a constant rate and would inflate
|
||||
/// any measured graph-event rate, and a record that is identical to the previous
|
||||
/// one is worth suppressing on a tick but never on a graph event.
|
||||
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
|
||||
pub enum EventKind {
|
||||
/// A registry observation: an add, a removal, a bind resolution, a `/proc`
|
||||
/// probe, or the server sync.
|
||||
Graph,
|
||||
/// The periodic clock sample. Carries no graph information; it exists so the
|
||||
/// readiness timeout and the AEC validation deadline have a clock.
|
||||
Tick,
|
||||
}
|
||||
|
||||
impl EventKind {
|
||||
pub fn code(self) -> &'static str {
|
||||
match self {
|
||||
Self::Graph => "graph",
|
||||
Self::Tick => "tick",
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
impl RegEvent {
|
||||
pub fn kind(&self) -> EventKind {
|
||||
match self {
|
||||
Self::Tick { .. } => EventKind::Tick,
|
||||
_ => EventKind::Graph,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Whether an applied event could have changed the projection.
|
||||
///
|
||||
/// The suppression rule of v3.5 §6.7 decision 2, in the one place that can
|
||||
/// enforce it: **a property update may be dropped only when the resulting
|
||||
/// [`Projection`] is identical to the current one.** The projection is a pure
|
||||
/// function of model state, so "state provably unchanged" *is* "projection
|
||||
/// identical" — which is what [`Outcome::Suppressed`] means and why the check
|
||||
/// is a cheap field comparison rather than building and diffing two snapshots.
|
||||
///
|
||||
/// Anything looser (dropping updates that do change state) breaks phase 4's
|
||||
/// no-coalescing contract, which needs to see the empty gap between an AEC
|
||||
/// module unload and a reload that reuses the index. Anything stricter
|
||||
/// (publishing on every `info`, including the state-only changes PipeWire
|
||||
/// emits constantly) inflates the O5 event rate with non-events.
|
||||
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
|
||||
pub enum Outcome {
|
||||
/// Model state may have changed; the caller must publish the projection.
|
||||
Applied,
|
||||
/// Model state provably did not change; publishing is optional and the
|
||||
/// adapter skips it.
|
||||
Suppressed,
|
||||
}
|
||||
|
||||
/// Which slot in the id index a live object occupies. `global_remove` gives
|
||||
/// only the id, so the index remembers what each id currently holds. A Node
|
||||
/// slot's serial may live in either the admitted or the withheld map.
|
||||
/// only the id, so the index remembers what each id currently holds. Every
|
||||
/// slot names its object by never-recycled serial.
|
||||
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
|
||||
enum Slot {
|
||||
Node(Serial),
|
||||
Port(Serial),
|
||||
Link(Serial),
|
||||
Client(Serial),
|
||||
Device,
|
||||
Device(Serial),
|
||||
}
|
||||
|
||||
/// The readiness epoch. A one-time transition out of [`Readiness::Waiting`];
|
||||
@@ -174,27 +287,55 @@ pub struct Projection {
|
||||
pub snapshot: GraphSnapshot,
|
||||
pub pipewire_pulse_pid: Option<u32>,
|
||||
pub graph_ready: bool,
|
||||
/// The sticky readiness epoch behind `graph_ready`. Carried so a consumer
|
||||
/// can tell the three not-ready causes apart — enumeration still in flight
|
||||
/// ([`Readiness::Waiting`]), a fail-closed timeout ([`Readiness::TimedOut`]),
|
||||
/// or a completed epoch momentarily blocked on a current obligation
|
||||
/// ([`Readiness::Complete`] with `graph_ready == false`). `graph_ready`
|
||||
/// alone collapses all three into "no". The phase-5 audit reports it as the
|
||||
/// epoch column; nothing gates on it.
|
||||
pub readiness: Readiness,
|
||||
}
|
||||
|
||||
/// A live Node: its global id (for link endpoint lookup) plus its bound
|
||||
/// properties once they arrive.
|
||||
#[derive(Clone, Debug, PartialEq, Eq)]
|
||||
struct NodeEntry {
|
||||
id: GlobalId,
|
||||
/// `None` while the bind is outstanding — withheld from the snapshot and
|
||||
/// an outstanding readiness obligation (v3.5 §6.7 decision 3).
|
||||
obs: Option<NodeObservation>,
|
||||
}
|
||||
|
||||
/// A live Device: its global id plus its bound properties once they arrive.
|
||||
#[derive(Clone, Debug, PartialEq, Eq)]
|
||||
struct DeviceEntry {
|
||||
id: GlobalId,
|
||||
/// `None` while the bind is outstanding. A node claiming this Device
|
||||
/// stays withheld until it is `Some` — the Device's `device.api` and
|
||||
/// `alsa.driver_name` are the authoritative inputs to `session_device`
|
||||
/// (v3.5 §6.7 decision 4), so classifying without them would be the same
|
||||
/// provisional answer the contract forbids.
|
||||
props: Option<DeviceProps>,
|
||||
}
|
||||
|
||||
/// The live model. Folds [`RegEvent`]s; project with [`RegistryModel::project`].
|
||||
#[derive(Clone, Debug)]
|
||||
pub struct RegistryModel {
|
||||
// Admitted objects, keyed by their never-recycled serial.
|
||||
nodes: BTreeMap<Serial, NodeSnapshot>,
|
||||
/// **Every** live Node, keyed by serial — admitted or withheld. Admission
|
||||
/// is decided at projection time from the entry's own state, so there is
|
||||
/// no admitted/withheld pair of maps to drift apart.
|
||||
nodes: BTreeMap<Serial, NodeEntry>,
|
||||
/// Every live Device, keyed by serial.
|
||||
devices: BTreeMap<Serial, DeviceEntry>,
|
||||
ports: BTreeMap<Serial, PortSnapshot>,
|
||||
links: BTreeMap<Serial, LinkSnapshot>,
|
||||
clients: BTreeMap<Serial, ClientSnapshot>,
|
||||
|
||||
/// Nodes held out of the snapshot pending their Device's resolution.
|
||||
withheld: BTreeMap<Serial, NodeObservation>,
|
||||
/// Links whose endpoints the adapter is still binding; the id is kept so
|
||||
/// removal and resolution can find them.
|
||||
pending_links: BTreeMap<Serial, GlobalId>,
|
||||
|
||||
/// Live Device global ids, ref-counted so a recycled id is only
|
||||
/// considered resolved while a Device actually holds it.
|
||||
resolved_devices: BTreeMap<GlobalId, usize>,
|
||||
|
||||
/// Insertion-ordered holders of each live global id. `global_remove`
|
||||
/// accounts for the oldest generation first (v3.4 §6.1.3).
|
||||
live_ids: BTreeMap<GlobalId, VecDeque<Slot>>,
|
||||
@@ -215,12 +356,11 @@ impl RegistryModel {
|
||||
pub fn new(now: Millis, timeout: Millis) -> Self {
|
||||
Self {
|
||||
nodes: BTreeMap::new(),
|
||||
devices: BTreeMap::new(),
|
||||
ports: BTreeMap::new(),
|
||||
links: BTreeMap::new(),
|
||||
clients: BTreeMap::new(),
|
||||
withheld: BTreeMap::new(),
|
||||
pending_links: BTreeMap::new(),
|
||||
resolved_devices: BTreeMap::new(),
|
||||
live_ids: BTreeMap::new(),
|
||||
probed_comm: BTreeMap::new(),
|
||||
server_synced: false,
|
||||
@@ -239,21 +379,22 @@ impl RegistryModel {
|
||||
///
|
||||
/// This is **dynamic**, not the sticky [`Readiness::Complete`] flag: it is
|
||||
/// true only when the initial enumeration has completed **and** there are
|
||||
/// no current obligations outstanding (a node withheld on an unresolved
|
||||
/// Device, or a Link still being bound). The distinction is the fix for
|
||||
/// Codex phase-3 review finding 1: a Link whose endpoints are still
|
||||
/// resolving is an **invisible edge** — it is absent from the snapshot,
|
||||
/// not merely dangling — so a decision made while one exists can miss real
|
||||
/// tainted ancestry and wrongly report a candidate eligible. Unresolved
|
||||
/// ancestry ⇒ fail closed is the governing invariant (v3.4 §6.1), and an
|
||||
/// unresolved Link is unresolved ancestry, so `graph_ready` must drop back
|
||||
/// to false whenever one is pending — even after the initial epoch.
|
||||
/// no current obligations outstanding (a node whose bind is outstanding, a
|
||||
/// node withheld on an unresolved Device, or a Link still being bound).
|
||||
/// The distinction is the fix for Codex phase-3 review finding 1: a Link
|
||||
/// whose endpoints are still resolving is an **invisible edge** — it is
|
||||
/// absent from the snapshot, not merely dangling — so a decision made
|
||||
/// while one exists can miss real tainted ancestry and wrongly report a
|
||||
/// candidate eligible. Unresolved ancestry ⇒ fail closed is the governing
|
||||
/// invariant (v3.4 §6.1), and round 8 adds the far more common case: an
|
||||
/// unbound node is an invisible *vertex*, which hides everything the edge
|
||||
/// case hides and its ownership besides.
|
||||
///
|
||||
/// [`Readiness::Complete`] stays sticky (it records that the initial
|
||||
/// enumeration happened, for logging and to distinguish "not started" from
|
||||
/// "momentarily churning"); `graph_ready` layers the dynamic obligation
|
||||
/// check on top. Downstream (phase 6) may debounce the brief blips a
|
||||
/// normal Link bind causes; the observer's job is to report the truth.
|
||||
/// normal bind causes; the observer's job is to report the truth.
|
||||
pub fn graph_ready(&self) -> bool {
|
||||
matches!(self.readiness, Readiness::Complete) && !self.obligations_outstanding()
|
||||
}
|
||||
@@ -266,102 +407,120 @@ impl RegistryModel {
|
||||
pulse_pid::candidate(&clients)
|
||||
}
|
||||
|
||||
/// Fold one observation into the model.
|
||||
pub fn apply(&mut self, event: RegEvent) {
|
||||
/// Fold one observation into the model. The returned [`Outcome`] tells the
|
||||
/// caller whether the projection can have changed; see [`Outcome`] for why
|
||||
/// that is the only sound place to enforce the suppression rule.
|
||||
pub fn apply(&mut self, event: RegEvent) -> Outcome {
|
||||
match event {
|
||||
RegEvent::NodeAdded(obs) => self.on_node_added(obs),
|
||||
RegEvent::NodeAdded { serial, id } => {
|
||||
self.push_id(id, Slot::Node(serial));
|
||||
self.nodes.insert(serial, NodeEntry { id, obs: None });
|
||||
// A node awaiting its bind is a fresh obligation, so this can
|
||||
// only ever *hold* readiness, never complete it — but the
|
||||
// re-check is cheap and keeps the invariant local.
|
||||
self.maybe_complete();
|
||||
Outcome::Applied
|
||||
}
|
||||
RegEvent::NodeInfo {
|
||||
serial,
|
||||
observation,
|
||||
} => self.on_node_info(serial, observation),
|
||||
RegEvent::PortAdded(port) => {
|
||||
self.push_id(port.id, Slot::Port(port.serial));
|
||||
self.ports.insert(port.serial, port);
|
||||
Outcome::Applied
|
||||
}
|
||||
RegEvent::ClientAdded(client) => {
|
||||
self.push_id(client.id, Slot::Client(client.serial));
|
||||
self.clients.insert(client.serial, client);
|
||||
// A new client can change the pulse candidate; the adapter
|
||||
// learns that via `pulse_pid_candidate`. No readiness effect.
|
||||
Outcome::Applied
|
||||
}
|
||||
RegEvent::DeviceAdded { id } => self.on_device_added(id),
|
||||
RegEvent::DeviceAdded { serial, id } => {
|
||||
self.push_id(id, Slot::Device(serial));
|
||||
self.devices.insert(serial, DeviceEntry { id, props: None });
|
||||
self.maybe_complete();
|
||||
Outcome::Applied
|
||||
}
|
||||
RegEvent::DeviceInfo { serial, props } => self.on_device_info(serial, props),
|
||||
RegEvent::LinkAdded {
|
||||
serial,
|
||||
id,
|
||||
endpoints,
|
||||
} => self.on_link_added(serial, id, endpoints),
|
||||
} => {
|
||||
self.on_link_added(serial, id, endpoints);
|
||||
Outcome::Applied
|
||||
}
|
||||
RegEvent::LinkEndpointsResolved { serial, endpoints } => {
|
||||
self.on_link_resolved(serial, endpoints)
|
||||
}
|
||||
RegEvent::ProcCommProbed { pid, comm } => {
|
||||
self.probed_comm.insert(pid, comm);
|
||||
let previous = self.probed_comm.insert(pid, comm.clone());
|
||||
if previous.as_ref() == Some(&comm) {
|
||||
Outcome::Suppressed
|
||||
} else {
|
||||
Outcome::Applied
|
||||
}
|
||||
}
|
||||
RegEvent::Removed { id } => self.on_removed(id),
|
||||
RegEvent::ServerSynced => {
|
||||
let already = self.server_synced;
|
||||
self.server_synced = true;
|
||||
self.maybe_complete();
|
||||
if already {
|
||||
Outcome::Suppressed
|
||||
} else {
|
||||
Outcome::Applied
|
||||
}
|
||||
}
|
||||
RegEvent::Tick { now } => {
|
||||
self.last_now = now;
|
||||
self.maybe_timeout(now);
|
||||
Outcome::Applied
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fn on_node_added(&mut self, obs: NodeObservation) {
|
||||
self.push_id(obs.id, Slot::Node(obs.serial));
|
||||
let resolved = obs
|
||||
.device_claim
|
||||
.device_id
|
||||
.is_some_and(|id| self.device_resolved(id));
|
||||
match classify::classify(&obs.device_claim, resolved) {
|
||||
Classification::Withhold { .. } => {
|
||||
self.withheld.insert(obs.serial, obs);
|
||||
}
|
||||
Classification::SessionDevice => self.admit_node(obs, true),
|
||||
Classification::NotADevice | Classification::NotSessionDevice => {
|
||||
self.admit_node(obs, false)
|
||||
}
|
||||
/// First resolution *and* every later property change (v3.5 §6.7
|
||||
/// decision 2). The model distinguishes them by what it already holds, so
|
||||
/// the adapter can forward every `info` callback unconditionally.
|
||||
fn on_node_info(&mut self, serial: Serial, observation: NodeObservation) -> Outcome {
|
||||
let Some(entry) = self.nodes.get_mut(&serial) else {
|
||||
// A late `info` for a node already removed. Re-inserting it here
|
||||
// would resurrect a dead node with no id index behind it.
|
||||
tracing::debug!(serial = serial.0, "observer: node info for an unknown node");
|
||||
return Outcome::Suppressed;
|
||||
};
|
||||
if entry.obs.as_ref() == Some(&observation) {
|
||||
// The state-only `info` callbacks PipeWire emits constantly: same
|
||||
// properties, so the projection is provably identical.
|
||||
return Outcome::Suppressed;
|
||||
}
|
||||
// Withholding a node adds an obligation; admitting one can never
|
||||
// complete readiness on its own, but re-check is cheap and keeps the
|
||||
// invariant local.
|
||||
entry.obs = Some(observation);
|
||||
// The first `info` retires this node's obligation, which can be the
|
||||
// last one outstanding.
|
||||
self.maybe_complete();
|
||||
Outcome::Applied
|
||||
}
|
||||
|
||||
fn admit_node(&mut self, obs: NodeObservation, session_device: bool) {
|
||||
let mut props = obs.props;
|
||||
props.session_device = session_device;
|
||||
self.nodes.insert(
|
||||
obs.serial,
|
||||
NodeSnapshot {
|
||||
serial: obs.serial,
|
||||
id: obs.id,
|
||||
name: obs.name,
|
||||
role: obs.role,
|
||||
props,
|
||||
},
|
||||
);
|
||||
}
|
||||
|
||||
fn on_device_added(&mut self, id: GlobalId) {
|
||||
self.push_id(id, Slot::Device);
|
||||
*self.resolved_devices.entry(id).or_insert(0) += 1;
|
||||
// Admit every node that was withheld waiting on exactly this Device.
|
||||
let ready: Vec<Serial> = self
|
||||
.withheld
|
||||
.iter()
|
||||
.filter(|(_, obs)| obs.device_claim.device_id == Some(id))
|
||||
.map(|(&serial, _)| serial)
|
||||
.collect();
|
||||
for serial in ready {
|
||||
if let Some(obs) = self.withheld.remove(&serial) {
|
||||
// Resolved now, so classify yields a terminal answer, never
|
||||
// Withhold again.
|
||||
let session_device = matches!(
|
||||
classify::classify(&obs.device_claim, true),
|
||||
Classification::SessionDevice
|
||||
);
|
||||
self.admit_node(obs, session_device);
|
||||
}
|
||||
fn on_device_info(&mut self, serial: Serial, props: DeviceProps) -> Outcome {
|
||||
let Some(entry) = self.devices.get_mut(&serial) else {
|
||||
tracing::debug!(
|
||||
serial = serial.0,
|
||||
"observer: device info for an unknown device"
|
||||
);
|
||||
return Outcome::Suppressed;
|
||||
};
|
||||
if entry.props.as_ref() == Some(&props) {
|
||||
return Outcome::Suppressed;
|
||||
}
|
||||
entry.props = Some(props);
|
||||
// Resolving a Device admits every node that was withheld on it —
|
||||
// which happens at projection time; here it can only retire
|
||||
// obligations.
|
||||
self.maybe_complete();
|
||||
Outcome::Applied
|
||||
}
|
||||
|
||||
fn on_link_added(&mut self, serial: Serial, id: GlobalId, endpoints: Option<LinkEndpoints>) {
|
||||
@@ -379,20 +538,23 @@ impl RegistryModel {
|
||||
self.maybe_complete();
|
||||
}
|
||||
|
||||
fn on_link_resolved(&mut self, serial: Serial, endpoints: LinkEndpoints) {
|
||||
fn on_link_resolved(&mut self, serial: Serial, endpoints: LinkEndpoints) -> Outcome {
|
||||
// `remove` also guards against a stale resolution for a Link already
|
||||
// gone: unknown serial ⇒ ignore.
|
||||
if let Some(id) = self.pending_links.remove(&serial) {
|
||||
self.links
|
||||
.insert(serial, link_snapshot(serial, id, endpoints));
|
||||
self.maybe_complete();
|
||||
Outcome::Applied
|
||||
} else {
|
||||
Outcome::Suppressed
|
||||
}
|
||||
}
|
||||
|
||||
fn on_removed(&mut self, id: GlobalId) {
|
||||
fn on_removed(&mut self, id: GlobalId) -> Outcome {
|
||||
let Some(queue) = self.live_ids.get_mut(&id) else {
|
||||
tracing::warn!(global_id = id.0, "observer: remove for an id we never saw");
|
||||
return;
|
||||
return Outcome::Suppressed;
|
||||
};
|
||||
// Oldest generation first — the id may be shared during a
|
||||
// missed-removal window.
|
||||
@@ -402,10 +564,7 @@ impl RegistryModel {
|
||||
}
|
||||
match slot {
|
||||
Some(Slot::Node(serial)) => {
|
||||
if self.nodes.remove(&serial).is_none() {
|
||||
// Was still withheld — drop the obligation.
|
||||
self.withheld.remove(&serial);
|
||||
}
|
||||
self.nodes.remove(&serial);
|
||||
}
|
||||
Some(Slot::Port(serial)) => {
|
||||
self.ports.remove(&serial);
|
||||
@@ -417,35 +576,77 @@ impl RegistryModel {
|
||||
Some(Slot::Client(serial)) => {
|
||||
self.clients.remove(&serial);
|
||||
}
|
||||
Some(Slot::Device) => {
|
||||
if let Some(count) = self.resolved_devices.get_mut(&id) {
|
||||
*count -= 1;
|
||||
if *count == 0 {
|
||||
self.resolved_devices.remove(&id);
|
||||
}
|
||||
}
|
||||
Some(Slot::Device(serial)) => {
|
||||
self.devices.remove(&serial);
|
||||
}
|
||||
None => {
|
||||
tracing::warn!(global_id = id.0, "observer: empty id slot on remove");
|
||||
return Outcome::Suppressed;
|
||||
}
|
||||
}
|
||||
// A removal can drain the last obligation (a withheld node or pending
|
||||
// link vanished before it resolved).
|
||||
// A removal can drain the last obligation (an unbound node, a node
|
||||
// withheld on a Device, or a pending link vanished before it
|
||||
// resolved).
|
||||
self.maybe_complete();
|
||||
Outcome::Applied
|
||||
}
|
||||
|
||||
fn push_id(&mut self, id: GlobalId, slot: Slot) {
|
||||
self.live_ids.entry(id).or_default().push_back(slot);
|
||||
}
|
||||
|
||||
fn device_resolved(&self, id: GlobalId) -> bool {
|
||||
self.resolved_devices.get(&id).is_some_and(|&n| n > 0)
|
||||
/// The bound properties of the Device a node claims by global id, or
|
||||
/// `None` when that claim is unresolved — which covers every fail-closed
|
||||
/// case at once: no such Device observed, its bind still outstanding, or
|
||||
/// **the id claimed by more than one live global**, where there is no way
|
||||
/// to tell whose properties these are (v3.4 §6.1.3).
|
||||
///
|
||||
/// ⚠️ The ambiguity test is "**exactly one** live global holds this id",
|
||||
/// not "exactly one live *Device*" (Codex phase-3r review, finding 2).
|
||||
/// The weaker test looks equivalent and is not: with `[Device, Port]` on
|
||||
/// one id — a missed removal, the same precondition as every other
|
||||
/// recycled-id hazard — it keeps answering with the older Device's
|
||||
/// properties, so a node claiming that id holds a stale
|
||||
/// `session_device = true`. That flag *removes* the node's owner keys and
|
||||
/// its fail-closed backstop, so a forwarder wearing it can put its output
|
||||
/// leg back on the eligible side: echo, from a lookup that was merely
|
||||
/// looking at the wrong object type.
|
||||
fn device_props(&self, id: GlobalId) -> Option<&DeviceProps> {
|
||||
let slots = self.live_ids.get(&id)?;
|
||||
if slots.len() != 1 {
|
||||
return None; // Ambiguous ⇒ unresolved ⇒ withheld.
|
||||
}
|
||||
let Slot::Device(serial) = slots.front()? else {
|
||||
// The id is live, but it is not a Device any more.
|
||||
return None;
|
||||
};
|
||||
self.devices.get(serial)?.props.as_ref()
|
||||
}
|
||||
|
||||
/// Classify one node's device claim against the currently resolved
|
||||
/// Devices. Recomputed per projection rather than cached at admission:
|
||||
/// the inputs (this node's props, its Device's props) both change over an
|
||||
/// object's lifetime now, and a cached classification is exactly the kind
|
||||
/// of stale provisional answer §6.1.3 forbids.
|
||||
fn classification(&self, obs: &NodeObservation) -> Classification {
|
||||
let device = obs
|
||||
.device_claim
|
||||
.device_id
|
||||
.and_then(|id| self.device_props(id));
|
||||
classify::classify(&obs.device_claim, device)
|
||||
}
|
||||
|
||||
/// Every obligation that must clear before the initial graph is trusted:
|
||||
/// no node withheld on an unresolved Device, no Link awaiting its bind.
|
||||
/// no node awaiting its bind, no node withheld on an unresolved Device,
|
||||
/// no Link awaiting its bind.
|
||||
fn obligations_outstanding(&self) -> bool {
|
||||
!self.withheld.is_empty() || !self.pending_links.is_empty()
|
||||
if !self.pending_links.is_empty() {
|
||||
return true;
|
||||
}
|
||||
self.nodes.values().any(|entry| match &entry.obs {
|
||||
None => true,
|
||||
Some(obs) => matches!(self.classification(obs), Classification::Withhold { .. }),
|
||||
})
|
||||
}
|
||||
|
||||
/// Completion needs no clock — only the sync flag and an empty obligation
|
||||
@@ -468,13 +669,34 @@ impl RegistryModel {
|
||||
if now >= self.deadline {
|
||||
self.readiness = Readiness::TimedOut;
|
||||
tracing::warn!(
|
||||
withheld = self.withheld.len(),
|
||||
unbound_nodes = self.unbound_node_count(),
|
||||
withheld = self.withheld_node_count(),
|
||||
pending_links = self.pending_links.len(),
|
||||
"observer: readiness epoch timed out with obligations outstanding — fail closed"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
/// Nodes whose bind has not delivered `info` yet — diagnostics only.
|
||||
fn unbound_node_count(&self) -> usize {
|
||||
self.nodes
|
||||
.values()
|
||||
.filter(|entry| entry.obs.is_none())
|
||||
.count()
|
||||
}
|
||||
|
||||
/// Nodes held out on an unresolved Device — diagnostics only.
|
||||
fn withheld_node_count(&self) -> usize {
|
||||
self.nodes
|
||||
.values()
|
||||
.filter(|entry| {
|
||||
entry.obs.as_ref().is_some_and(|obs| {
|
||||
matches!(self.classification(obs), Classification::Withhold { .. })
|
||||
})
|
||||
})
|
||||
.count()
|
||||
}
|
||||
|
||||
/// pipewire-pulse's PID from the current clients, validated against the
|
||||
/// probed `comm`. `None` whenever anything is ambiguous or unconfirmed —
|
||||
/// the safe answer (key 4 unusable).
|
||||
@@ -485,9 +707,34 @@ impl RegistryModel {
|
||||
}
|
||||
|
||||
/// Project the current state into the taint engine's inputs.
|
||||
///
|
||||
/// A node enters the snapshot only if its bind has delivered `info`
|
||||
/// **and** its device claim classifies terminally; anything else is
|
||||
/// withheld (and is already holding `graph_ready` false).
|
||||
pub fn project(&self) -> Projection {
|
||||
let nodes: Vec<NodeSnapshot> = self
|
||||
.nodes
|
||||
.iter()
|
||||
.filter_map(|(&serial, entry)| {
|
||||
let obs = entry.obs.as_ref()?;
|
||||
let session_device = match self.classification(obs) {
|
||||
Classification::Withhold { .. } => return None,
|
||||
Classification::SessionDevice => true,
|
||||
Classification::NotADevice | Classification::NotSessionDevice => false,
|
||||
};
|
||||
let mut props = obs.props.clone();
|
||||
props.session_device = session_device;
|
||||
Some(NodeSnapshot {
|
||||
serial,
|
||||
id: entry.id,
|
||||
name: obs.name.clone(),
|
||||
role: obs.role,
|
||||
props,
|
||||
})
|
||||
})
|
||||
.collect();
|
||||
let snapshot = GraphSnapshot::new(
|
||||
self.nodes.values().cloned().collect(),
|
||||
nodes,
|
||||
self.ports.values().cloned().collect(),
|
||||
self.links.values().cloned().collect(),
|
||||
self.clients.values().cloned().collect(),
|
||||
@@ -496,6 +743,7 @@ impl RegistryModel {
|
||||
snapshot,
|
||||
pipewire_pulse_pid: self.pulse_pid(),
|
||||
graph_ready: self.graph_ready(),
|
||||
readiness: self.readiness,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+821
-109
File diff suppressed because it is too large
Load Diff
@@ -36,6 +36,10 @@ pub struct Graph {
|
||||
/// (GStreamer opens one per stream) pass clients explicitly instead.
|
||||
client_by_app: BTreeMap<u32, GlobalId>,
|
||||
client_by_module: BTreeMap<u64, GlobalId>,
|
||||
/// Native (non-Pulse-emulated) clients, whose `pipewire.sec.pid` is the
|
||||
/// app's **own** pid rather than pipewire-pulse's. See
|
||||
/// [`Graph::native_client_node`].
|
||||
native_client_by_app: BTreeMap<u32, GlobalId>,
|
||||
session_client: Option<GlobalId>,
|
||||
}
|
||||
|
||||
@@ -84,6 +88,35 @@ impl Graph {
|
||||
id
|
||||
}
|
||||
|
||||
/// A **native PipeWire** client's stream: `client.id` on the node, **no
|
||||
/// `application.process.id`**, and the app's real pid only on the Client
|
||||
/// as `pipewire.sec.pid`.
|
||||
///
|
||||
/// ⚠️ This is what an ordinary app actually looks like when it does not go
|
||||
/// through pipewire-pulse — measured for mpv on its default ao and for
|
||||
/// peerspeak's own playback stream. [`Graph::app_node`] models the
|
||||
/// Pulse-emulated shape, where the pid is on the node and the Client's
|
||||
/// `sec_pid` is the *daemon's*; both shapes are live on this host, and
|
||||
/// only this one exercises key 4's Client fallback (round 10, R10-3).
|
||||
pub fn native_client_node(&mut self, name: &str, role: MediaRole, pid: u32) -> NodeRef {
|
||||
let client = match self.native_client_by_app.get(&pid) {
|
||||
Some(id) => *id,
|
||||
None => {
|
||||
let id = self.client(Some(pid));
|
||||
self.native_client_by_app.insert(pid, id);
|
||||
id
|
||||
}
|
||||
};
|
||||
self.node(
|
||||
name,
|
||||
role,
|
||||
NodeProps {
|
||||
client_id: Some(client),
|
||||
..NodeProps::default()
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
/// An ordinary application stream: its own client, its own PID.
|
||||
pub fn app_node(&mut self, name: &str, role: MediaRole, pid: u32) -> NodeRef {
|
||||
let client = self.client_of_app(pid);
|
||||
@@ -152,11 +185,43 @@ impl Graph {
|
||||
self.node(name, role, app(client, pid))
|
||||
}
|
||||
|
||||
/// A peerspeak-owned node carrying **both** ownership carriers, as a
|
||||
/// live one does. `name` gets the real `node.name` prefix so the fixture
|
||||
/// cannot pass on the property alone.
|
||||
pub fn peerspeak_node(&mut self, name: &str, pid: u32) -> NodeRef {
|
||||
let client = self.client_of_app(pid);
|
||||
let name = format!("{}{name}_{pid}", super::PEERSPEAK_OWNED_NODE_PREFIX);
|
||||
self.node(&name, MediaRole::StreamOutput, peerspeak_owned(client, pid))
|
||||
}
|
||||
|
||||
/// Both ownership carriers on a node of **any** role — an impostor, or a
|
||||
/// producer-side tagging bug. Only [`MediaRole::StreamOutput`] makes it a
|
||||
/// taint root (round 10, R10-1); every other role must be ignored, and
|
||||
/// these are the fixtures that prove it.
|
||||
pub fn peerspeak_tagged_node(&mut self, name: &str, role: MediaRole, pid: u32) -> NodeRef {
|
||||
let client = self.client_of_app(pid);
|
||||
let name = format!("{}{name}_{pid}", super::PEERSPEAK_OWNED_NODE_PREFIX);
|
||||
self.node(&name, role, peerspeak_owned(client, pid))
|
||||
}
|
||||
|
||||
/// Carrier 1 alone: the `peerspeak.owned` property present, the
|
||||
/// `node.name` prefix absent. What the engine sees for a node it had to
|
||||
/// bind to observe (v3.5 §6.7).
|
||||
pub fn peerspeak_node_prop_only(&mut self, name: &str, pid: u32) -> NodeRef {
|
||||
let client = self.client_of_app(pid);
|
||||
self.node(name, MediaRole::StreamOutput, peerspeak_owned(client, pid))
|
||||
}
|
||||
|
||||
/// Carrier 2 alone: the `node.name` prefix present, the property absent
|
||||
/// — indistinguishable from an ordinary app in every other respect.
|
||||
/// This is the case that survives the F1 observation defect, and the
|
||||
/// reason round 8 added a second carrier at all.
|
||||
pub fn peerspeak_node_name_only(&mut self, role: &str, pid: u32) -> NodeRef {
|
||||
let client = self.client_of_app(pid);
|
||||
let name = format!("{}{role}_{pid}", super::PEERSPEAK_OWNED_NODE_PREFIX);
|
||||
self.node(&name, MediaRole::StreamOutput, app(client, pid))
|
||||
}
|
||||
|
||||
pub fn node(&mut self, name: &str, role: MediaRole, props: NodeProps) -> NodeRef {
|
||||
let id = self.id();
|
||||
self.node_with_id(name, role, id, props)
|
||||
|
||||
+230
-38
@@ -100,8 +100,11 @@
|
||||
pub mod owner;
|
||||
pub mod snapshot;
|
||||
|
||||
// `pub` so the phase-5 audit's pure tests can drive the auditor with the same
|
||||
// graph builder the taint fixtures use — one fixture vocabulary, so an audit
|
||||
// test and a taint test describing the same topology cannot drift apart.
|
||||
#[cfg(test)]
|
||||
mod fixture;
|
||||
pub mod fixture;
|
||||
#[cfg(test)]
|
||||
mod tests;
|
||||
|
||||
@@ -120,6 +123,44 @@ pub const CAPTURE_SINK_PREFIX: &str = "pixelpass_capture_";
|
||||
/// what `pulse.module.id` is for (v3.4 §5.2 correction 4).
|
||||
pub const ECHO_CANCEL_GROUP_PREFIX: &str = "echo-cancel-";
|
||||
|
||||
/// Ownership carrier 1: the node property peerspeak sets on everything it
|
||||
/// plays (v3.5 §5.1). Read at the observer boundary, which is the only place
|
||||
/// that touches raw property names — see [`super::observer`].
|
||||
///
|
||||
/// ⚠️ **Cross-repo wire contract.** peerspeak emits this; it does not depend
|
||||
/// on this crate, nor this crate on it. The values are pinned in
|
||||
/// `tests/fixtures/ownership-tag-contract.txt`, committed byte-identical in
|
||||
/// both repos, and asserted by [`tests::ownership_carriers_match_the_cross_repo_fixture`].
|
||||
/// The producer's matching constants live in peerspeak
|
||||
/// `src/audio/ownership.rs`. Changing either is a both-repos-same-session
|
||||
/// change that invalidates the phase 5 matrix.
|
||||
pub const PEERSPEAK_OWNED_PROP: &str = "peerspeak.owned";
|
||||
|
||||
/// The value peerspeak emits for [`PEERSPEAK_OWNED_PROP`], and the **only**
|
||||
/// value this consumer reads as owned.
|
||||
///
|
||||
/// ⚠️ This doc used to say the opposite — that any truthy value counted, on
|
||||
/// the theory that treating an unexpected value as "owned" is the fail-closed
|
||||
/// direction. R10-4 removed that leniency and the round-10 review caught the
|
||||
/// prose surviving it here and in the shared fixture. The theory is wrong:
|
||||
/// leniency buys false-positive *exclusion*, not safety, and it let any
|
||||
/// process suppress a rival application's audio from the share with a
|
||||
/// property it did not have to spell right. Fail-closed on this feature is
|
||||
/// about **ancestry** — an unresolvable graph is not eligible — not about
|
||||
/// parsing. The matching lives in the observer's `peerspeak_owned`, which is
|
||||
/// deliberately *not* the lenient `truthy` used for PipeWire's own booleans.
|
||||
pub const PEERSPEAK_OWNED_VALUE: &str = "1";
|
||||
|
||||
/// Ownership carrier 2: a `node.name` prefix (v3.5 §5.1, round 8).
|
||||
///
|
||||
/// Matched as a **union** with [`PEERSPEAK_OWNED_PROP`] — either one makes a
|
||||
/// node peerspeak-owned. Two carriers because a property is invisible to the
|
||||
/// registry `global` event and recoverable only by binding the node (v3.5
|
||||
/// §6.7), which is precisely how the phase-5 gate failed; this one is
|
||||
/// announced directly. A union is also the fail-closed direction: a missed
|
||||
/// tag leaks call audio into the share, a spurious one only over-excludes.
|
||||
pub const PEERSPEAK_OWNED_NODE_PREFIX: &str = "peerspeak_owned_";
|
||||
|
||||
/// Why a node is tainted or excluded. Stable machine-readable codes: this
|
||||
/// value is the phase 5 audit output, the phase 6 status event, and the
|
||||
/// eventual answer to "why isn't this app being shared?".
|
||||
@@ -375,39 +416,36 @@ pub fn evaluate(
|
||||
ctx: &ExclusionCtx,
|
||||
prior: &StickyState,
|
||||
) -> (Decisions, StickyState) {
|
||||
let components = OwnerComponents::build(snapshot, ctx.pipewire_pulse_pid);
|
||||
let keys = owner::OwnerKeyIndex::build(snapshot, ctx.pipewire_pulse_pid);
|
||||
// Built once and shared: it carries the Client → `pipewire.sec.pid` index
|
||||
// that key 4 falls back to (round 10, R10-3), so the components and the
|
||||
// key index must be derived from the *same* one or they would disagree
|
||||
// about which nodes are bounded.
|
||||
let owner_ctx = owner::OwnerCtx::new(snapshot, ctx.pipewire_pulse_pid);
|
||||
let components = OwnerComponents::build(snapshot, &owner_ctx);
|
||||
let keys = owner::OwnerKeyIndex::build(snapshot, &owner_ctx);
|
||||
|
||||
let mut taint: BTreeMap<Serial, Reason> = BTreeMap::new();
|
||||
let mut sticky_serials: BTreeSet<Serial> = BTreeSet::new();
|
||||
|
||||
seed_local_roots(snapshot, ctx, &mut taint);
|
||||
seed_sticky(
|
||||
// Pass 1 — the fail-closed view. Every decision is made from this one, so
|
||||
// "we could not see" counts as taint.
|
||||
let (taint, sticky_serials) = compute_taint(
|
||||
snapshot,
|
||||
ctx,
|
||||
&keys,
|
||||
prior,
|
||||
&components,
|
||||
&mut taint,
|
||||
&mut sticky_serials,
|
||||
prior,
|
||||
Uncertainty::FailsClosed,
|
||||
);
|
||||
|
||||
// Monotone fixpoint: every step only adds taint, or lowers a node's
|
||||
// reason priority, both of which are bounded. Link propagation and the
|
||||
// owner bridge feed each other — a bridged output leg has downstream
|
||||
// links, and a downstream monitor reader bridges to its own siblings —
|
||||
// so neither can be run once.
|
||||
let edges = downstream_edges(snapshot, &mut taint);
|
||||
loop {
|
||||
let mut changed = false;
|
||||
changed |= propagate_links(&edges.edges, &mut taint);
|
||||
changed |= propagate_owner_bridge(&keys, &components, &edges, &mut taint);
|
||||
changed |= propagate_unresolved_owner(snapshot, &keys, &edges, &mut taint);
|
||||
if !changed {
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
let decisions = build_decisions(snapshot, ctx, &taint, &sticky_serials);
|
||||
|
||||
// Pass 2 — the evidence-only view, and the only thing sticky state is
|
||||
// ever built from (see [`Uncertainty`]).
|
||||
let (evidence, _) = compute_taint(
|
||||
snapshot,
|
||||
ctx,
|
||||
&keys,
|
||||
&components,
|
||||
prior,
|
||||
Uncertainty::Ignored,
|
||||
);
|
||||
// ⚠️ Readiness gates **retirement only**, never addition (Codex rounds
|
||||
// 1 and 2, which caught the two halves of this in turn). An object
|
||||
// missing from an untrustworthy snapshot has not been observed to
|
||||
@@ -416,10 +454,105 @@ pub fn evaluate(
|
||||
// *observed* during a not-ready epoch is real — a reader can consume
|
||||
// and buffer the call and then vanish before readiness — so discarding
|
||||
// additions was the same defect pointing the other way.
|
||||
let next_sticky = build_sticky(snapshot, &keys, &components, &taint, prior, ctx.graph_ready);
|
||||
let next_sticky = build_sticky(
|
||||
snapshot,
|
||||
&keys,
|
||||
&components,
|
||||
&evidence,
|
||||
prior,
|
||||
ctx.graph_ready,
|
||||
);
|
||||
(decisions, next_sticky)
|
||||
}
|
||||
|
||||
/// Whether a pass treats "we could not see" as taint.
|
||||
///
|
||||
/// **Both passes exist because stickiness is a claim about history, and
|
||||
/// uncertainty is not history.** A node tainted only because the graph was
|
||||
/// mid-enumeration has had nothing observed about it; remembering that as
|
||||
/// taint forever is over-exclusion with no evidence behind it, and phase 3r's
|
||||
/// bind-everything observer makes the window it happens in systematically
|
||||
/// wide (every node is withheld until its bind resolves, so any link observed
|
||||
/// across that gap raises [`Reason::UnresolvedAncestry`] on its input side).
|
||||
/// Measured on a live desktop: a hardware sink acquired a permanent sticky
|
||||
/// taint at every startup, from one link seen while its output node was still
|
||||
/// unbound.
|
||||
///
|
||||
/// Retiring by *reason code* is not enough, because uncertainty launders
|
||||
/// itself: an unresolved node propagates [`Reason::TaintedUpstream`] to its
|
||||
/// downstream, and that reason is indistinguishable from real contamination
|
||||
/// once recorded. So the split is by **provenance** — the sticky pass never
|
||||
/// raises an uncertainty root at all, and nothing derived from one can reach
|
||||
/// it. Decisions are unaffected: they are made from the fail-closed pass,
|
||||
/// which is unchanged.
|
||||
#[derive(Clone, Copy, PartialEq, Eq, Debug)]
|
||||
enum Uncertainty {
|
||||
/// Unresolved ancestry and an unbounded tainted reader are taint
|
||||
/// (v3.4 §6.1, §6.1.1, §6.1.4).
|
||||
FailsClosed,
|
||||
/// Only positively observed contamination counts.
|
||||
Ignored,
|
||||
}
|
||||
|
||||
/// One taint fixpoint over the snapshot. The `uncertainty` mode decides
|
||||
/// whether absence of evidence is treated as evidence of contamination.
|
||||
fn compute_taint(
|
||||
snapshot: &GraphSnapshot,
|
||||
ctx: &ExclusionCtx,
|
||||
keys: &owner::OwnerKeyIndex,
|
||||
components: &OwnerComponents,
|
||||
prior: &StickyState,
|
||||
uncertainty: Uncertainty,
|
||||
) -> (BTreeMap<Serial, Reason>, BTreeSet<Serial>) {
|
||||
let fails_closed = uncertainty == Uncertainty::FailsClosed;
|
||||
let mut taint: BTreeMap<Serial, Reason> = BTreeMap::new();
|
||||
let mut sticky_serials: BTreeSet<Serial> = BTreeSet::new();
|
||||
|
||||
seed_local_roots(snapshot, ctx, &mut taint);
|
||||
if fails_closed {
|
||||
for serial in ambiguous_id_nodes(snapshot) {
|
||||
raise(&mut taint, serial, Reason::UnresolvedAncestry);
|
||||
}
|
||||
}
|
||||
seed_sticky(
|
||||
snapshot,
|
||||
keys,
|
||||
prior,
|
||||
components,
|
||||
&mut taint,
|
||||
&mut sticky_serials,
|
||||
);
|
||||
|
||||
// Edges are built identically in both passes — receiver status is a
|
||||
// topological fact and must not depend on the mode, or the owner bridge
|
||||
// would see two different graphs.
|
||||
let mut unresolved_input: BTreeSet<Serial> = BTreeSet::new();
|
||||
let edges = downstream_edges(snapshot, &mut unresolved_input);
|
||||
if fails_closed {
|
||||
for serial in unresolved_input {
|
||||
raise(&mut taint, serial, Reason::UnresolvedAncestry);
|
||||
}
|
||||
}
|
||||
|
||||
// Monotone fixpoint: every step only adds taint, or lowers a node's
|
||||
// reason priority, both of which are bounded. Link propagation and the
|
||||
// owner bridge feed each other — a bridged output leg has downstream
|
||||
// links, and a downstream monitor reader bridges to its own siblings —
|
||||
// so neither can be run once.
|
||||
loop {
|
||||
let mut changed = false;
|
||||
changed |= propagate_links(&edges.edges, &mut taint);
|
||||
changed |= propagate_owner_bridge(keys, components, &edges, &mut taint);
|
||||
if fails_closed {
|
||||
changed |= propagate_unresolved_owner(snapshot, keys, &edges, &mut taint);
|
||||
}
|
||||
if !changed {
|
||||
break;
|
||||
}
|
||||
}
|
||||
(taint, sticky_serials)
|
||||
}
|
||||
|
||||
/// Roots that are visible on the node itself.
|
||||
fn seed_local_roots(
|
||||
snapshot: &GraphSnapshot,
|
||||
@@ -430,16 +563,73 @@ fn seed_local_roots(
|
||||
if let Some(reason) = local_root_reason(node, ctx) {
|
||||
raise(taint, node.serial, reason);
|
||||
}
|
||||
// A node whose own global id is ambiguous cannot be the reliable
|
||||
// endpoint of any link, so its ancestry is unresolvable.
|
||||
if snapshot.node_by_id(node.id) == Some(IdLookup::Ambiguous) {
|
||||
raise(taint, node.serial, Reason::UnresolvedAncestry);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Nodes whose own global id is ambiguous: they cannot be the reliable
|
||||
/// endpoint of any link, so their ancestry is unresolvable. Uncertainty, not
|
||||
/// evidence — see [`Uncertainty`].
|
||||
fn ambiguous_id_nodes(snapshot: &GraphSnapshot) -> BTreeSet<Serial> {
|
||||
snapshot
|
||||
.nodes()
|
||||
.filter(|node| snapshot.node_by_id(node.id) == Some(IdLookup::Ambiguous))
|
||||
.map(|node| node.serial)
|
||||
.collect()
|
||||
}
|
||||
|
||||
/// Does this node carry either ownership carrier? **Tag presence only** — it
|
||||
/// deliberately says nothing about whether the tag is honoured, which is
|
||||
/// `local_root_reason`'s business (round 10 restricts that to producers).
|
||||
/// Split out so the "is it tagged?" and "does the tag count?" questions can
|
||||
/// be tested, and reported, independently.
|
||||
pub fn is_peerspeak_tagged(node: &NodeSnapshot) -> bool {
|
||||
node.props.peerspeak_owned
|
||||
|| node
|
||||
.name
|
||||
.as_deref()
|
||||
.is_some_and(|name| name.starts_with(PEERSPEAK_OWNED_NODE_PREFIX))
|
||||
}
|
||||
|
||||
/// Nodes carrying an ownership carrier that `local_root_reason` **ignored**
|
||||
/// because the node is not a producer (round 10, R10-1). Ascending by serial.
|
||||
///
|
||||
/// Purely diagnostic — nothing in the engine consumes it. It exists because
|
||||
/// R10-1 turns a formerly load-bearing tag into a no-op, and a silently
|
||||
/// ignored tag has exactly two causes, both of which someone wants to know
|
||||
/// about: peerspeak tagging a node it should not (a producer-side bug this
|
||||
/// would otherwise hide), or another process impersonating the tag (the F2
|
||||
/// attack, now defanged but still worth seeing).
|
||||
pub fn misplaced_ownership_tags(snapshot: &GraphSnapshot) -> Vec<&NodeSnapshot> {
|
||||
let mut tagged: Vec<&NodeSnapshot> = snapshot
|
||||
.nodes()
|
||||
.filter(|node| node.role != MediaRole::StreamOutput && is_peerspeak_tagged(node))
|
||||
.collect();
|
||||
tagged.sort_by_key(|node| node.serial);
|
||||
tagged
|
||||
}
|
||||
|
||||
fn local_root_reason(node: &NodeSnapshot, ctx: &ExclusionCtx) -> Option<Reason> {
|
||||
if node.props.peerspeak_owned {
|
||||
// The two ownership carriers, as a union (v3.5 §5.1). Kept here rather
|
||||
// than folded together at the observer boundary so that the union is a
|
||||
// pure, directly-testable rule: an adapter that collapsed both into the
|
||||
// one `peerspeak_owned` bool would make each carrier untestable alone,
|
||||
// which is exactly how phase 3r's row 1 nearly gated nothing.
|
||||
//
|
||||
// ⚠️ **Producer roles only** (round 10, R10-1). Neither carrier is a
|
||||
// security boundary — both are strings any unprivileged process can put
|
||||
// on its own node — so an unrestricted root is a denial of the whole
|
||||
// feature: an unlinked `Stream/Input/Audio` named `peerspeak_owned_x`
|
||||
// is a tainted *reader* with no owner bound to it, which fails every
|
||||
// candidate closed machine-wide (Codex phase-1 F2, reproduced live).
|
||||
// Restricting the root to `Stream/Output/Audio` costs nothing real —
|
||||
// peerspeak only ever tags playback streams — and the attack needs the
|
||||
// impostor to be a plausible playback node instead, which taints only
|
||||
// its own descendants. The AEC's virtual sink/source is unaffected: it
|
||||
// roots on [`Reason::AecIdentity`] below, by module id, not by this tag.
|
||||
// A tag on a non-producer falls through: ignored for taint, but not
|
||||
// nothing — it is either a peerspeak bug or an impostor, and
|
||||
// [`misplaced_ownership_tags`] surfaces it so neither is silent.
|
||||
if is_peerspeak_tagged(node) && node.role == MediaRole::StreamOutput {
|
||||
return Some(Reason::PeerspeakOwned);
|
||||
}
|
||||
if let (Some(module), Some(aec)) = (node.props.pulse_module_id, ctx.aec_module_id)
|
||||
@@ -560,7 +750,7 @@ fn nodes_of_client(
|
||||
/// `output node → input nodes`, resolving snapshot-local ids. An endpoint
|
||||
/// that does not resolve taints the *other* end as unresolved ancestry when
|
||||
/// that other end is the input side — we cannot know what is feeding it.
|
||||
fn downstream_edges(snapshot: &GraphSnapshot, taint: &mut BTreeMap<Serial, Reason>) -> Edges {
|
||||
fn downstream_edges(snapshot: &GraphSnapshot, unresolved_input: &mut BTreeSet<Serial>) -> Edges {
|
||||
let mut edges: BTreeMap<Serial, Vec<Serial>> = BTreeMap::new();
|
||||
let mut receivers: BTreeSet<Serial> = BTreeSet::new();
|
||||
for link in snapshot.links() {
|
||||
@@ -572,8 +762,10 @@ fn downstream_edges(snapshot: &GraphSnapshot, taint: &mut BTreeMap<Serial, Reaso
|
||||
receivers.insert(to);
|
||||
}
|
||||
(_, Some(IdLookup::Unique(to))) => {
|
||||
// Something feeds this node and we cannot say what.
|
||||
raise(taint, to, Reason::UnresolvedAncestry);
|
||||
// Something feeds this node and we cannot say what. Reported
|
||||
// rather than raised here, because whether "cannot say" is
|
||||
// taint depends on which pass is running ([`Uncertainty`]).
|
||||
unresolved_input.insert(to);
|
||||
receivers.insert(to);
|
||||
}
|
||||
(_, Some(IdLookup::Ambiguous)) => {
|
||||
|
||||
+190
-19
@@ -67,10 +67,71 @@
|
||||
//! Grouping is **transitive** (union-find). That is the fail-closed
|
||||
//! direction: bigger owner components mean more taint, never less.
|
||||
|
||||
use std::collections::BTreeMap;
|
||||
use std::collections::{BTreeMap, BTreeSet};
|
||||
|
||||
use super::snapshot::{GlobalId, GraphSnapshot, NodeSnapshot, Serial};
|
||||
|
||||
/// Everything owner-key derivation needs from outside a single node.
|
||||
///
|
||||
/// Introduced by round 10 (R10-3). Before it, `keys_of` read only node
|
||||
/// properties, and key 4 was therefore available **only** to nodes carrying
|
||||
/// `application.process.id` — which native PipeWire clients do not. mpv on its
|
||||
/// default ao, and peerspeak's own playback stream, expose nothing but
|
||||
/// `client.id`, so both were *unbounded*, and the moment any tainted reader
|
||||
/// existed anywhere, `propagate_unresolved_owner` excluded every one of them.
|
||||
/// Measured: an untagged mpv went from eligible (alone) to `unresolved-owner`
|
||||
/// the instant peerspeak played audio. That is "native-PipeWire apps are never
|
||||
/// shareable", which is not a feature.
|
||||
///
|
||||
/// The missing pid is not missing at all — it is one hop away, on the node's
|
||||
/// **Client**, as `pipewire.sec.pid`, and already in the snapshot.
|
||||
pub struct OwnerCtx {
|
||||
pub pipewire_pulse_pid: Option<u32>,
|
||||
/// `client.id` → that Client's `pipewire.sec.pid`.
|
||||
///
|
||||
/// Clients whose global id is **ambiguous** (two live objects claiming it,
|
||||
/// i.e. the observer missed a removal) are deliberately absent: resolving
|
||||
/// an ambiguous id to a pid would attribute a node to whichever Client won
|
||||
/// a coin toss, and inventing an owner key is the one direction that can
|
||||
/// *reduce* taint. Absent ⇒ unbounded ⇒ fails closed, as before.
|
||||
client_pids: BTreeMap<GlobalId, u32>,
|
||||
}
|
||||
|
||||
impl OwnerCtx {
|
||||
pub fn new(snapshot: &GraphSnapshot, pipewire_pulse_pid: Option<u32>) -> Self {
|
||||
let mut client_pids: BTreeMap<GlobalId, u32> = BTreeMap::new();
|
||||
// ⚠️ Tracked separately from `client_pids`, and that is the point: a
|
||||
// Client with no `sec_pid` still *claims* its id. Detecting duplicates
|
||||
// by looking in the pid map would let a pid-less first claimant leave
|
||||
// no trace, so the next Client claiming the same id would look unique
|
||||
// and its pid would be used — resolving an ambiguous id, which is the
|
||||
// one guess this guard exists to refuse. Pid-less Clients are ordinary
|
||||
// (the session manager's is one).
|
||||
let mut seen: BTreeSet<GlobalId> = BTreeSet::new();
|
||||
for client in snapshot.clients() {
|
||||
if !seen.insert(client.id) {
|
||||
// Two Clients claiming one id: drop it entirely rather than
|
||||
// pick. See the field docs.
|
||||
client_pids.remove(&client.id);
|
||||
continue;
|
||||
}
|
||||
if let Some(pid) = client.sec_pid {
|
||||
client_pids.insert(client.id, pid);
|
||||
}
|
||||
}
|
||||
Self {
|
||||
pipewire_pulse_pid,
|
||||
client_pids,
|
||||
}
|
||||
}
|
||||
|
||||
/// The `pipewire.sec.pid` of this node's Client, if it has one and that
|
||||
/// Client's id is unambiguous.
|
||||
fn client_pid(&self, node: &NodeSnapshot) -> Option<u32> {
|
||||
self.client_pids.get(&node.props.client_id?).copied()
|
||||
}
|
||||
}
|
||||
|
||||
/// Which key bridged two legs. Ordered strongest first; the `Ord` derive is
|
||||
/// load-bearing for "report the strongest shared key".
|
||||
#[derive(Clone, Copy, PartialEq, Eq, PartialOrd, Ord, Debug, Hash)]
|
||||
@@ -84,6 +145,16 @@ pub enum OwnerKey {
|
||||
impl OwnerKey {
|
||||
/// Stable, machine-readable — this ends up in the phase 5 audit output
|
||||
/// and the phase 6 status event.
|
||||
///
|
||||
/// ⚠️ **Known imprecision, deliberately not fixed here.** `ProcessId` now
|
||||
/// covers two sources — the node's `application.process.id` and its
|
||||
/// Client's `pipewire.sec.pid` (see [`keys_of`]) — so a bridge reported as
|
||||
/// `application.process.id` may in fact have resolved on the Client's
|
||||
/// protected pid. Pre-existing since R10-3 made the Client a fallback, and
|
||||
/// widened by the review's finding 1 making it a union. Splitting it would
|
||||
/// add a code to a set that is explicitly a stable contract for the audit
|
||||
/// output and the "why isn't this app being shared?" answer, so it wants
|
||||
/// its own decision rather than a drive-by.
|
||||
pub fn code(self) -> &'static str {
|
||||
match self {
|
||||
Self::LinkGroup => "node.link-group",
|
||||
@@ -106,7 +177,7 @@ enum KeyValue {
|
||||
/// A key that is present but unusable (the pipewire-pulse PID; a coarse key
|
||||
/// on a device node) is **absent** here — that is the whole mechanism of the
|
||||
/// two exceptions.
|
||||
fn keys_of(node: &NodeSnapshot, pipewire_pulse_pid: Option<u32>) -> Vec<(OwnerKey, KeyValue)> {
|
||||
fn keys_of(node: &NodeSnapshot, ctx: &OwnerCtx) -> Vec<(OwnerKey, KeyValue)> {
|
||||
let mut out = Vec::new();
|
||||
if let Some(group) = &node.props.link_group {
|
||||
out.push((OwnerKey::LinkGroup, KeyValue::Text(group.clone())));
|
||||
@@ -122,14 +193,48 @@ fn keys_of(node: &NodeSnapshot, pipewire_pulse_pid: Option<u32>) -> Vec<(OwnerKe
|
||||
if let Some(client) = node.props.client_id {
|
||||
out.push((OwnerKey::ClientId, KeyValue::Num(u64::from(client.0))));
|
||||
}
|
||||
if let Some(pid) = node.props.process_id {
|
||||
// Exception 1. Note the fail-closed asymmetry when the daemon PID is
|
||||
// unknown (`None`): the exception does *not* fire, key 4 applies to
|
||||
// everything, and Pulse modules fuse into one owner. That is broad
|
||||
// over-exclusion — annoying and safe — which is the direction v3.4
|
||||
// §6.1.2's failure-mode paragraph asks for.
|
||||
if Some(pid) != pipewire_pulse_pid {
|
||||
out.push((OwnerKey::ProcessId, KeyValue::Num(u64::from(pid))));
|
||||
// Key 4, from the node **and** from its Client (round 10, R10-3; made a
|
||||
// union rather than a fallback by the round-10 review, finding 1).
|
||||
//
|
||||
// ⚠️ **A union, not `node.or_else(client)`, and the difference is a leak.**
|
||||
// The node's `application.process.id` is client-controlled and optional;
|
||||
// the Client's `pipewire.sec.pid` is `pipewire.*`, protected, and the only
|
||||
// one that can carry a soundness argument (the same reason
|
||||
// `propagate_unresolved_owner` sweeps everything for an unbounded reader).
|
||||
// Letting the node's value *replace* the Client's meant one process using
|
||||
// two Clients could escape the bridge entirely: its tainted reader reports
|
||||
// a bogus node pid, its output leg omits the node pid and falls back to
|
||||
// the Client's real one, the two legs are bounded by different values, so
|
||||
// they neither bridge nor trip the unbounded sweep — and the output stays
|
||||
// eligible while re-emitting the call. Carrying both values costs nothing
|
||||
// and closes it: a leg that presents *either* value bridges.
|
||||
//
|
||||
// ⚠️ **Exception 1 applies to each value independently, and that is the
|
||||
// whole risk here.** Measured on this host: 15 unrelated Clients share
|
||||
// `sec_pid` 2528, which is pipewire-pulse's own — every Pulse-emulated app
|
||||
// has one. Suppressing it per value is what keeps the union from fusing
|
||||
// all fifteen into a single owner while still keeping each app's real
|
||||
// per-app pid. For the common Pulse shape (node pid = the app's, Client
|
||||
// `sec_pid` = the daemon's) the union therefore reduces to exactly the
|
||||
// node's pid, as before.
|
||||
//
|
||||
// Note the fail-closed asymmetry when the daemon PID is unknown (`None`):
|
||||
// the exception does *not* fire, key 4 applies to everything, and Pulse
|
||||
// modules fuse into one owner. That is broad over-exclusion — annoying and
|
||||
// safe — which is the direction v3.4 §6.1.2's failure-mode paragraph asks
|
||||
// for.
|
||||
for pid in [node.props.process_id, ctx.client_pid(node)]
|
||||
.into_iter()
|
||||
.flatten()
|
||||
{
|
||||
if Some(pid) == ctx.pipewire_pulse_pid {
|
||||
continue;
|
||||
}
|
||||
let key = (OwnerKey::ProcessId, KeyValue::Num(u64::from(pid)));
|
||||
// The two agree far more often than not; a duplicate entry would be
|
||||
// harmless but would make the audit's key list read oddly.
|
||||
if !out.contains(&key) {
|
||||
out.push(key);
|
||||
}
|
||||
}
|
||||
out
|
||||
@@ -151,8 +256,74 @@ fn keys_of(node: &NodeSnapshot, pipewire_pulse_pid: Option<u32>) -> Vec<(OwnerKe
|
||||
/// nothing else relates them. Its sibling output leg cannot be found, so
|
||||
/// the engine must fail closed rather than declare it clean
|
||||
/// (v3.4 §6.1.1, final paragraph).
|
||||
pub fn owner_is_bounded(node: &NodeSnapshot, pipewire_pulse_pid: Option<u32>) -> bool {
|
||||
keys_of(node, pipewire_pulse_pid)
|
||||
///
|
||||
/// # 🔴 OPEN, phase-6 blocking — the key union can *reduce* taint here
|
||||
///
|
||||
/// **Round 11 review, finding 1. Verified correct; deliberately not fixed in
|
||||
/// that round.** Round 10 made key 4 a union of the node's
|
||||
/// `application.process.id` and its Client's `pipewire.sec.pid`, and the claim
|
||||
/// that this was "strictly additive" was too strong: the same key list also
|
||||
/// feeds *this* predicate, so adding a value can move a node from unbounded to
|
||||
/// bounded, and `propagate_unresolved_owner`'s global sweep is triggered by an
|
||||
/// **un**bounded tainted reader. Concretely:
|
||||
///
|
||||
/// 1. A tainted reader's node claims the pipewire-pulse PID while its Client
|
||||
/// holds a real protected PID `A`. Under `or_else` the node's value won and
|
||||
/// exception 1 suppressed it, leaving the reader unbounded; under the union
|
||||
/// it is bounded by `A`.
|
||||
/// 2. Its process's output leg uses a second Client whose id is **ambiguous**
|
||||
/// (the observer missed a removal), so no protected PID is available — but
|
||||
/// the leg claims a bogus `application.process.id` `B`, which bounds it.
|
||||
/// 3. Neither the bridge nor the sweep fires, and the output stays eligible
|
||||
/// while re-emitting the call.
|
||||
///
|
||||
/// It cannot leak today: `evaluate()` is reached only by the dry-run audit,
|
||||
/// which creates no links. It becomes live when phase 6 consumes eligibility.
|
||||
///
|
||||
/// **Why it is not fixed yet.** The principled repair is provenance: a
|
||||
/// self-claimed `application.process.id` is not a *sound* bound, only the
|
||||
/// protected keys are. But applying that bluntly makes every Pulse-emulated
|
||||
/// app unbounded — their Client's `sec_pid` is the daemon's and suppressed, so
|
||||
/// the node's own claim is their only per-app identity — which re-triggers the
|
||||
/// §6.1.1 mass over-exclusion the whole design is built to avoid, and would
|
||||
/// make the eligible half of the §5.1 matrix empty.
|
||||
///
|
||||
/// The targeted rule that closes the path above without that cost: **a node
|
||||
/// whose Client cannot be resolved at all must not be bounded by its own
|
||||
/// self-claimed PID.** An ambiguous Client already means "we do not know who
|
||||
/// owns this", and a self-claim must not paper over it; a Pulse app's Client
|
||||
/// *is* resolved (to the daemon's PID, then suppressed), so it keeps its
|
||||
/// bound. Implementing it needs `OwnerCtx` to distinguish "resolved" from
|
||||
/// "absent", and `OwnerKeyIndex` to carry boundedness separately from the key
|
||||
/// set, since bridging must keep using the full union.
|
||||
///
|
||||
/// ⚠️ Do this **with the §5.1 matrix data in hand**, not before: the whole
|
||||
/// question is how much over-exclusion the rule actually causes on a real
|
||||
/// graph, and that is measurable rather than arguable.
|
||||
///
|
||||
/// ## Round 12 — the deferral holds, and "resolved" has a trap in it
|
||||
///
|
||||
/// Codex re-examined this and agreed the deferral is defensible while
|
||||
/// `evaluate()` is audit-only, and that the rule above closes the recorded path
|
||||
/// without unbounding normal Pulse-emulated apps — **but only under one
|
||||
/// reading of "resolves"**, and the wrong reading reintroduces the hole:
|
||||
///
|
||||
/// - ✅ "Resolved" must mean **an unambiguous Client that yields
|
||||
/// `Some(pipewire.sec.pid)`**, taken *before* the pipewire-pulse suppression
|
||||
/// step. A Pulse app then still has the daemon's protected PID as
|
||||
/// provenance, even though that value is omitted from the bridge keys, so it
|
||||
/// stays bounded and the eligible half survives.
|
||||
/// - ❌ **Do not** implement it as "a unique Client object exists". A unique
|
||||
/// Client with `sec_pid = None` would satisfy that test while providing no
|
||||
/// protected identity at all, leaving exactly the self-claimed-PID hole this
|
||||
/// rule is meant to close.
|
||||
///
|
||||
/// So the matrix needs five Client cases, not two: **absent**, **ambiguous**,
|
||||
/// **unique but pid-less**, **resolved-native**, and
|
||||
/// **resolved-to-pipewire-pulse**. The third is the one that distinguishes the
|
||||
/// two readings, and it is the row a two-case matrix would silently skip.
|
||||
pub fn owner_is_bounded(node: &NodeSnapshot, ctx: &OwnerCtx) -> bool {
|
||||
keys_of(node, ctx)
|
||||
.iter()
|
||||
.any(|(key, _)| *key != OwnerKey::ClientId)
|
||||
}
|
||||
@@ -168,11 +339,11 @@ pub struct OwnerKeyIndex {
|
||||
}
|
||||
|
||||
impl OwnerKeyIndex {
|
||||
pub fn build(snapshot: &GraphSnapshot, pipewire_pulse_pid: Option<u32>) -> Self {
|
||||
pub fn build(snapshot: &GraphSnapshot, ctx: &OwnerCtx) -> Self {
|
||||
Self {
|
||||
keys: snapshot
|
||||
.nodes()
|
||||
.map(|node| (node.serial, keys_of(node, pipewire_pulse_pid)))
|
||||
.map(|node| (node.serial, keys_of(node, ctx)))
|
||||
.collect(),
|
||||
}
|
||||
}
|
||||
@@ -252,10 +423,10 @@ impl OwnerKeyIndex {
|
||||
pub fn strongest_shared_key(
|
||||
a: &NodeSnapshot,
|
||||
b: &NodeSnapshot,
|
||||
pipewire_pulse_pid: Option<u32>,
|
||||
ctx: &OwnerCtx,
|
||||
) -> Option<OwnerKey> {
|
||||
let a_keys = keys_of(a, pipewire_pulse_pid);
|
||||
let b_keys = keys_of(b, pipewire_pulse_pid);
|
||||
let a_keys = keys_of(a, ctx);
|
||||
let b_keys = keys_of(b, ctx);
|
||||
// `keys_of` yields strongest-first, so the first match is the strongest.
|
||||
a_keys.iter().find_map(|(key, value)| {
|
||||
b_keys
|
||||
@@ -279,7 +450,7 @@ pub struct OwnerComponents {
|
||||
}
|
||||
|
||||
impl OwnerComponents {
|
||||
pub fn build(snapshot: &GraphSnapshot, pipewire_pulse_pid: Option<u32>) -> Self {
|
||||
pub fn build(snapshot: &GraphSnapshot, ctx: &OwnerCtx) -> Self {
|
||||
let serials: Vec<Serial> = snapshot.nodes().map(|n| n.serial).collect();
|
||||
let index: BTreeMap<Serial, usize> =
|
||||
serials.iter().enumerate().map(|(i, s)| (*s, i)).collect();
|
||||
@@ -290,7 +461,7 @@ impl OwnerComponents {
|
||||
let mut buckets: BTreeMap<(OwnerKey, KeyValue), Vec<usize>> = BTreeMap::new();
|
||||
for node in snapshot.nodes() {
|
||||
let slot = index[&node.serial];
|
||||
for (key, value) in keys_of(node, pipewire_pulse_pid) {
|
||||
for (key, value) in keys_of(node, ctx) {
|
||||
buckets.entry((key, value)).or_default().push(slot);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -87,6 +87,20 @@ impl MediaRole {
|
||||
pub fn is_candidate(self) -> bool {
|
||||
matches!(self, Self::StreamOutput)
|
||||
}
|
||||
|
||||
/// Stable machine-readable code for the audit output. Not the raw
|
||||
/// `media.class`: `Other` has no single one, and the audit's codes are a
|
||||
/// contract with the matrix, not with PipeWire.
|
||||
pub fn code(self) -> &'static str {
|
||||
match self {
|
||||
Self::StreamOutput => "stream-output",
|
||||
Self::StreamInput => "stream-input",
|
||||
Self::Sink => "sink",
|
||||
Self::Source => "source",
|
||||
Self::Duplex => "duplex",
|
||||
Self::Other => "other",
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// The subset of node properties the engine actually reasons about.
|
||||
@@ -97,8 +111,17 @@ impl MediaRole {
|
||||
/// on this feature means "not tainted".
|
||||
#[derive(Clone, Debug, Default, PartialEq, Eq)]
|
||||
pub struct NodeProps {
|
||||
/// `peerspeak.owned` is present and truthy (v3.4 §5.1). A correctness
|
||||
/// mechanism, explicitly *not* a security boundary.
|
||||
/// `peerspeak.owned` is present and **exactly**
|
||||
/// [`super::PEERSPEAK_OWNED_VALUE`] (v3.4 §5.1, tightened by round 10's
|
||||
/// R10-4 — it is not "present and truthy", and the round-10 review found
|
||||
/// this doc still saying so). A correctness mechanism, explicitly *not* a
|
||||
/// security boundary.
|
||||
///
|
||||
/// ⚠️ **Ownership carrier 1 of 2, so this being `false` does not mean
|
||||
/// "not peerspeak's".** Carrier 2 is the [`NodeSnapshot::name`] prefix
|
||||
/// [`super::PEERSPEAK_OWNED_NODE_PREFIX`], matched as a union in
|
||||
/// `local_root_reason`. Read that function, not this field, to answer
|
||||
/// "is this node owned?".
|
||||
pub peerspeak_owned: bool,
|
||||
/// `pulse.module.id`, parsed as `u64` — never `u32`, per v3.4 §5.2's
|
||||
/// parse-defensively note and the phase 0a truncation bug.
|
||||
|
||||
+662
-3
@@ -15,7 +15,7 @@
|
||||
use std::collections::BTreeSet;
|
||||
|
||||
use super::fixture::{Graph, NodeRef, PULSE_PID, app};
|
||||
use super::owner::{OwnerKey, strongest_shared_key};
|
||||
use super::owner::{OwnerCtx, OwnerKey, strongest_shared_key};
|
||||
use super::snapshot::{MediaRole, NodeProps, PortDirection, Serial};
|
||||
use super::{Decisions, Eligibility, ExclusionCtx, ObjectRef, Reason, StickyState, evaluate};
|
||||
|
||||
@@ -176,6 +176,217 @@ fn peerspeak_tagged_nodes_are_excluded_and_plain_apps_are_not() {
|
||||
assert_tainted(&decisions, sink, "tainted-upstream");
|
||||
}
|
||||
|
||||
/// Each ownership carrier must work **alone** (v3.5 §5.1).
|
||||
///
|
||||
/// ⚠️ The phase-3r lesson, applied deliberately: a gate that asserts a value
|
||||
/// two sources can satisfy gates neither. `peerspeak_tagged_nodes_…` above
|
||||
/// uses nodes carrying both carriers, so it would keep passing if either
|
||||
/// were deleted. These are the rows that actually pin them.
|
||||
#[test]
|
||||
fn either_ownership_carrier_alone_taints_the_node() {
|
||||
let mut graph = Graph::new();
|
||||
let sink = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
// Carrier 1: the property, on a node whose name says nothing.
|
||||
let prop_only = graph.peerspeak_node_prop_only("some-playback-stream", 7);
|
||||
// Carrier 2: the name prefix, property absent — the F1 case.
|
||||
let name_only = graph.peerspeak_node_name_only("mpv", 31_284);
|
||||
let firefox = graph.app_node("firefox", MediaRole::StreamOutput, 11_114);
|
||||
for node in [prop_only, name_only, firefox] {
|
||||
graph.link(node, sink);
|
||||
}
|
||||
|
||||
assert_partition(
|
||||
&run(&graph, &ctx()),
|
||||
&[("firefox", firefox)],
|
||||
&[
|
||||
("prop_only", prop_only, "peerspeak-owned"),
|
||||
("name_only", name_only, "peerspeak-owned"),
|
||||
],
|
||||
);
|
||||
}
|
||||
|
||||
/// **R10-1, the F2 fix.** Neither carrier is a security boundary — both are
|
||||
/// strings any unprivileged process can set on its own node — so the tag is
|
||||
/// honoured only on `Stream/Output/Audio`, the one role peerspeak ever tags.
|
||||
///
|
||||
/// Without the restriction, a tagged `Stream/Input/Audio` **with no links at
|
||||
/// all** is a tainted *reader* (`receivers` includes nodes by role, no link
|
||||
/// required), and an unbounded one, so `propagate_unresolved_owner` fails
|
||||
/// every candidate on the machine closed. That is a whole-feature denial from
|
||||
/// an unprivileged process, reproduced live during the phase-1 review.
|
||||
#[test]
|
||||
fn an_ownership_tag_on_a_non_producer_is_not_a_taint_root() {
|
||||
for role in [
|
||||
MediaRole::StreamInput,
|
||||
MediaRole::Sink,
|
||||
MediaRole::Source,
|
||||
MediaRole::Duplex,
|
||||
MediaRole::Other,
|
||||
] {
|
||||
let mut graph = Graph::new();
|
||||
let sink = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
let firefox = graph.app_node("firefox", MediaRole::StreamOutput, 11_114);
|
||||
graph.link(firefox, sink);
|
||||
// Deliberately unlinked: the F2 shape needs no edges whatsoever.
|
||||
let impostor = graph.peerspeak_tagged_node("rogue", role, 4_242);
|
||||
|
||||
let decisions = run(&graph, &ctx());
|
||||
assert_untainted(&decisions, impostor);
|
||||
assert!(
|
||||
decisions.taint.is_empty(),
|
||||
"{role:?} impostor tainted something: {:?}",
|
||||
decisions.taint.keys().collect::<Vec<_>>()
|
||||
);
|
||||
// The whole point: the eligible half stays non-empty.
|
||||
assert_partition(&decisions, &[("firefox", firefox)], &[]);
|
||||
}
|
||||
}
|
||||
|
||||
/// **The live F2 reproduction, verbatim.** The measured impostor was an
|
||||
/// *unbounded* reader — `client.id` present, `application.process.id` absent
|
||||
/// — which is what turns "one bogus tainted node" into "nothing on this
|
||||
/// machine is shareable": `propagate_unresolved_owner` cannot prove any
|
||||
/// candidate independent of a reader it cannot attribute to an owner.
|
||||
///
|
||||
/// Measured before the fix: `BASELINE eligible=1 excluded=[]` →
|
||||
/// `WITH IMPOSTOR eligible=0 excluded=[firefox → unresolved-owner]`.
|
||||
///
|
||||
/// Distinct from the row above, which uses a *bounded* impostor and so would
|
||||
/// still pass if only the cheap half of the fix were present.
|
||||
#[test]
|
||||
fn an_unbounded_tagged_impostor_cannot_exclude_a_bystander_app() {
|
||||
let mut graph = Graph::new();
|
||||
let sink = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
let firefox = graph.app_node("firefox", MediaRole::StreamOutput, 11_114);
|
||||
let mpv = graph.app_node("mpv", MediaRole::StreamOutput, 31_284);
|
||||
for node in [firefox, mpv] {
|
||||
graph.link(node, sink);
|
||||
}
|
||||
|
||||
let baseline = run(&graph, &ctx());
|
||||
assert_partition(&baseline, &[("firefox", firefox), ("mpv", mpv)], &[]);
|
||||
|
||||
// Both carriers, no pid, no links — everything an unprivileged process
|
||||
// can arrange for itself in one `pw-cli` invocation.
|
||||
let rogue_client = graph.client(Some(PULSE_PID));
|
||||
let impostor = graph.node(
|
||||
&format!("{}rogue_4242", super::PEERSPEAK_OWNED_NODE_PREFIX),
|
||||
MediaRole::StreamInput,
|
||||
NodeProps {
|
||||
peerspeak_owned: true,
|
||||
client_id: Some(rogue_client),
|
||||
..NodeProps::default()
|
||||
},
|
||||
);
|
||||
|
||||
let decisions = run(&graph, &ctx());
|
||||
assert_untainted(&decisions, impostor);
|
||||
assert_partition(&decisions, &[("firefox", firefox), ("mpv", mpv)], &[]);
|
||||
}
|
||||
|
||||
/// A tag that R10-1 ignores is still reported, so that neither a peerspeak
|
||||
/// tagging bug nor an impersonation attempt is silent.
|
||||
#[test]
|
||||
fn ignored_ownership_tags_are_surfaced_for_diagnostics() {
|
||||
let mut graph = Graph::new();
|
||||
let sink = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
let call = graph.peerspeak_node("call", 7);
|
||||
graph.link(call, sink);
|
||||
let impostor = graph.peerspeak_tagged_node("rogue", MediaRole::StreamInput, 4_242);
|
||||
|
||||
let snapshot = graph.build();
|
||||
let misplaced: Vec<Serial> = super::misplaced_ownership_tags(&snapshot)
|
||||
.iter()
|
||||
.map(|node| node.serial)
|
||||
.collect();
|
||||
|
||||
// Exactly the ignored one: the honoured producer is not "misplaced".
|
||||
assert_eq!(misplaced, vec![impostor.serial]);
|
||||
assert_ne!(impostor.serial, call.serial);
|
||||
}
|
||||
|
||||
/// The prefix is a **prefix**, not a substring: an unrelated app must not be
|
||||
/// excluded because the literal appears somewhere in its name. Over-exclusion
|
||||
/// is the safe direction, but it is still wrong, and the phase-5 gate now
|
||||
/// asserts exact partitions in both halves.
|
||||
#[test]
|
||||
fn the_owned_prefix_matches_only_at_the_start_of_node_name() {
|
||||
let mut graph = Graph::new();
|
||||
let sink = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
let impostor = graph.app_node(
|
||||
&format!("recorder-of-{}stuff", super::PEERSPEAK_OWNED_NODE_PREFIX),
|
||||
MediaRole::StreamOutput,
|
||||
11_114,
|
||||
);
|
||||
graph.link(impostor, sink);
|
||||
|
||||
assert_partition(&run(&graph, &ctx()), &[("impostor", impostor)], &[]);
|
||||
}
|
||||
|
||||
/// The consumer half of the cross-repo contract test (impl plan §3
|
||||
/// requirement 2). peerspeak runs the mirror of this against a byte-identical
|
||||
/// copy of the same file, and asserts the environment a real child `Command`
|
||||
/// would carry produces exactly these literals.
|
||||
///
|
||||
/// This proves the two repos agree on the *literals*. That pixelpass actually
|
||||
/// *listens* is proven by the two carrier tests above, and against the live
|
||||
/// graph by the phase 5 dry-run.
|
||||
#[test]
|
||||
fn ownership_carriers_match_the_cross_repo_fixture() {
|
||||
const FIXTURE: &str = include_str!("../../../tests/fixtures/ownership-tag-contract.txt");
|
||||
|
||||
let pinned: Vec<(&str, &str)> = FIXTURE
|
||||
.lines()
|
||||
.map(str::trim)
|
||||
.filter(|line| !line.is_empty() && !line.starts_with('#'))
|
||||
.map(|line| line.split_once('=').expect("fixture line is key=value"))
|
||||
.collect();
|
||||
|
||||
// ⚠️ Refuse a duplicated key rather than resolving it (Codex phase-1
|
||||
// review, finding 3). This side takes the first match and peerspeak's
|
||||
// took the last, so a duplicate in a byte-identical file could leave both
|
||||
// repos green having selected *different* contracts.
|
||||
for (index, (key, _)) in pinned.iter().enumerate() {
|
||||
assert!(
|
||||
!pinned[..index].iter().any(|(seen, _)| seen == key),
|
||||
"fixture defines {key:?} twice; the two repos would disagree on which wins"
|
||||
);
|
||||
}
|
||||
let get = |key: &str| -> &str {
|
||||
pinned
|
||||
.iter()
|
||||
.find(|(k, _)| *k == key)
|
||||
.unwrap_or_else(|| panic!("fixture has no key {key:?}"))
|
||||
.1
|
||||
};
|
||||
|
||||
assert_eq!(super::PEERSPEAK_OWNED_PROP, get("prop_key"));
|
||||
assert_eq!(super::PEERSPEAK_OWNED_NODE_PREFIX, get("node_name_prefix"));
|
||||
// ⚠️ **Equality, and that is now the whole rule**: carrier 1 is matched
|
||||
// exactly, not as "anything but false/0" (round 10, R10-4). This assert
|
||||
// used to be followed by a weaker `value != "false" && value != "0"`
|
||||
// check, which described a leniency that no longer exists — the round-10
|
||||
// review's finding 6, and a real trap: a future producer reading the old
|
||||
// fixture prose could emit "true" and silently lose this carrier.
|
||||
//
|
||||
// That this consumer actually *listens* to the fixture's value, through
|
||||
// the production observer wiring rather than a helper, is asserted by
|
||||
// `observer::adapter::tests::the_fixture_value_is_the_only_owned_spelling`.
|
||||
assert_eq!(super::PEERSPEAK_OWNED_VALUE, get("prop_value"));
|
||||
|
||||
// And the fixture's own worked example must be one this engine excludes,
|
||||
// through carrier 2, exactly as written in the shared file.
|
||||
let mut graph = Graph::new();
|
||||
let sink = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
let example = graph.app_node(get("node_name_example"), MediaRole::StreamOutput, 31_284);
|
||||
graph.link(example, sink);
|
||||
assert_partition(
|
||||
&run(&graph, &ctx()),
|
||||
&[],
|
||||
&[("example", example, "peerspeak-owned")],
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn aec_identity_is_exact_equality_and_other_modules_stay_eligible() {
|
||||
let mut graph = Graph::new();
|
||||
@@ -507,8 +718,9 @@ fn owner_key_union_falls_through_a_present_but_unequal_key() {
|
||||
snapshot.node(b.serial).unwrap(),
|
||||
);
|
||||
assert_ne!(a.props.client_id, b.props.client_id);
|
||||
let owner_ctx = OwnerCtx::new(&snapshot, Some(PULSE_PID));
|
||||
assert_eq!(
|
||||
strongest_shared_key(a, b, Some(PULSE_PID)),
|
||||
strongest_shared_key(a, b, &owner_ctx),
|
||||
Some(OwnerKey::ProcessId)
|
||||
);
|
||||
}
|
||||
@@ -519,11 +731,12 @@ fn the_strongest_shared_key_wins_when_several_match() {
|
||||
let a = graph.group_node("a", MediaRole::StreamInput, "g", 500);
|
||||
let b = graph.group_node("b", MediaRole::StreamOutput, "g", 500);
|
||||
let snapshot = graph.build();
|
||||
let owner_ctx = OwnerCtx::new(&snapshot, Some(PULSE_PID));
|
||||
assert_eq!(
|
||||
strongest_shared_key(
|
||||
snapshot.node(a.serial).unwrap(),
|
||||
snapshot.node(b.serial).unwrap(),
|
||||
Some(PULSE_PID)
|
||||
&owner_ctx
|
||||
),
|
||||
Some(OwnerKey::LinkGroup)
|
||||
);
|
||||
@@ -560,6 +773,321 @@ fn the_pipewire_pulse_pid_does_not_fuse_unrelated_modules() {
|
||||
assert_untainted(&decisions, b_in);
|
||||
}
|
||||
|
||||
/// **R10-3, the fix.** A native PipeWire client puts no
|
||||
/// `application.process.id` on its node — only `client.id` — so before the
|
||||
/// Client fallback it had no key 4, was therefore *unbounded*, and
|
||||
/// `propagate_unresolved_owner` excluded it the moment any tainted reader
|
||||
/// existed anywhere on the machine.
|
||||
///
|
||||
/// Measured live: an untagged mpv was eligible alone, and became
|
||||
/// `unresolved-owner` the instant peerspeak played audio. Since peerspeak
|
||||
/// playing audio is the only situation in which this feature runs at all, that
|
||||
/// amounted to "native-PipeWire apps are never shareable".
|
||||
#[test]
|
||||
fn a_native_client_is_bounded_by_its_clients_sec_pid() {
|
||||
let mut graph = Graph::new();
|
||||
let hw = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
let call = graph.peerspeak_node("peerspeak", 7);
|
||||
graph.link(call, hw);
|
||||
|
||||
// The tainted reader that arms the unresolved-owner arm. Bounded itself
|
||||
// (a real pid), exactly as the live `sunshine` was — so this is the
|
||||
// bounded-reader arm, not the keyless-reader one.
|
||||
let sunshine = graph.app_node("sunshine", MediaRole::StreamInput, 3_838);
|
||||
graph.link(hw, sunshine);
|
||||
|
||||
// mpv on its default ao: client.id only, pid on the Client.
|
||||
let mpv = graph.native_client_node("mpv", MediaRole::StreamOutput, 31_284);
|
||||
graph.link(mpv, hw);
|
||||
|
||||
assert_partition(
|
||||
&run(&graph, &ctx()),
|
||||
&[("mpv", mpv)],
|
||||
&[("call", call, "peerspeak-owned")],
|
||||
);
|
||||
}
|
||||
|
||||
/// The fallback must bridge a native app's *own* legs, or it has bought
|
||||
/// boundedness without buying correctness: an app that reads the call and
|
||||
/// re-emits it on a second native node would be declared clean.
|
||||
#[test]
|
||||
fn the_sec_pid_fallback_still_bridges_a_native_apps_own_legs() {
|
||||
let mut graph = Graph::new();
|
||||
let hw = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
let call = graph.peerspeak_node("peerspeak", 7);
|
||||
graph.link(call, hw);
|
||||
|
||||
// One native process, two nodes, no link between them — the forwarder
|
||||
// shape, in the native flavour.
|
||||
let leg_in = graph.native_client_node("forwarder-in", MediaRole::StreamInput, 50_000);
|
||||
let leg_out = graph.native_client_node("forwarder-out", MediaRole::StreamOutput, 50_000);
|
||||
graph.link(hw, leg_in);
|
||||
|
||||
let decisions = run(&graph, &ctx());
|
||||
assert_tainted(&decisions, leg_out, "tainted-owner-bridge");
|
||||
assert_partition(
|
||||
&decisions,
|
||||
&[],
|
||||
&[
|
||||
("call", call, "peerspeak-owned"),
|
||||
("forwarder-out", leg_out, "tainted-owner-bridge"),
|
||||
],
|
||||
);
|
||||
}
|
||||
|
||||
/// **The risk the fallback creates, and the guard on it.** Every
|
||||
/// Pulse-emulated Client carries pipewire-pulse's own PID as `sec_pid` —
|
||||
/// measured, 15 unrelated Clients sharing 2528 on this host. An unguarded
|
||||
/// fallback would give all of them key 4 with the *same* value and fuse them
|
||||
/// into one owner, so a single tainted Pulse app would exclude every other
|
||||
/// Pulse app on the machine.
|
||||
///
|
||||
/// Exception 1 therefore applies to the fallback exactly as it does to the
|
||||
/// node's own property. Without that, this row goes red.
|
||||
#[test]
|
||||
fn the_sec_pid_fallback_does_not_fuse_every_pulse_client() {
|
||||
let mut graph = Graph::new();
|
||||
let hw = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
let call = graph.peerspeak_node("peerspeak", 7);
|
||||
graph.link(call, hw);
|
||||
|
||||
// Three unrelated Pulse-emulated apps, each on its own Client, none
|
||||
// exposing a node-level pid — so each can only reach key 4 through its
|
||||
// Client, whose sec_pid is the daemon's.
|
||||
let pulse_app = |graph: &mut Graph, name: &str, role| {
|
||||
let client = graph.client(Some(PULSE_PID));
|
||||
graph.node(
|
||||
name,
|
||||
role,
|
||||
NodeProps {
|
||||
client_id: Some(client),
|
||||
..NodeProps::default()
|
||||
},
|
||||
)
|
||||
};
|
||||
// One of them reads the tainted sink; the other two must not care.
|
||||
let reader = pulse_app(&mut graph, "recorder", MediaRole::StreamInput);
|
||||
graph.link(hw, reader);
|
||||
let other_a = pulse_app(&mut graph, "player-a", MediaRole::StreamOutput);
|
||||
let other_b = pulse_app(&mut graph, "player-b", MediaRole::StreamOutput);
|
||||
|
||||
let decisions = run(&graph, &ctx());
|
||||
// They are unbounded (`client.id` alone never bounds an owner), so the
|
||||
// fail-closed arm still excludes them — but as `unresolved-owner`, NOT as
|
||||
// `tainted-owner-bridge`. That distinction is the whole assertion: a
|
||||
// bridge reason here would mean the daemon pid had fused three unrelated
|
||||
// applications into one owner, and unlike fail-closed exclusion, fusion
|
||||
// does not go away when the apps are given real pids
|
||||
// (`distinct_sec_pids_bound_each_native_app_separately` is that half).
|
||||
assert_tainted(&decisions, other_a, "unresolved-owner");
|
||||
assert_tainted(&decisions, other_b, "unresolved-owner");
|
||||
for node in [other_a, other_b] {
|
||||
assert_ne!(
|
||||
decisions.taint.get(&node.serial).map(|e| e.reason.code()),
|
||||
Some("tainted-owner-bridge"),
|
||||
"the daemon pid must not bridge unrelated Pulse clients"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
/// The same three apps, given **real per-app** `sec_pid`s: now the fallback
|
||||
/// fires, all three are bounded, and only the one actually reading the call is
|
||||
/// affected. This is the row that proves the guard above suppresses the daemon
|
||||
/// pid *specifically* rather than disabling the fallback outright.
|
||||
#[test]
|
||||
fn distinct_sec_pids_bound_each_native_app_separately() {
|
||||
let mut graph = Graph::new();
|
||||
let hw = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
let call = graph.peerspeak_node("peerspeak", 7);
|
||||
graph.link(call, hw);
|
||||
|
||||
let reader = graph.native_client_node("recorder", MediaRole::StreamInput, 6_001);
|
||||
graph.link(hw, reader);
|
||||
let other_a = graph.native_client_node("player-a", MediaRole::StreamOutput, 6_002);
|
||||
let other_b = graph.native_client_node("player-b", MediaRole::StreamOutput, 6_003);
|
||||
|
||||
assert_partition(
|
||||
&run(&graph, &ctx()),
|
||||
&[("player-a", other_a), ("player-b", other_b)],
|
||||
&[("call", call, "peerspeak-owned")],
|
||||
);
|
||||
}
|
||||
|
||||
/// An **ambiguous** `client.id` — two live Clients claiming it, meaning the
|
||||
/// observer missed a removal — must not yield a fallback pid. Inventing an
|
||||
/// owner key is the one direction that can *reduce* taint, so resolving the
|
||||
/// ambiguity by coin toss is the wrong kind of guess.
|
||||
#[test]
|
||||
fn an_ambiguous_client_id_yields_no_fallback_pid() {
|
||||
let mut graph = Graph::new();
|
||||
let hw = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
let call = graph.peerspeak_node("peerspeak", 7);
|
||||
graph.link(call, hw);
|
||||
let sunshine = graph.app_node("sunshine", MediaRole::StreamInput, 3_838);
|
||||
graph.link(hw, sunshine);
|
||||
|
||||
// Two Clients, one id, distinct real pids.
|
||||
let shared_id = graph.client(Some(6_010));
|
||||
graph.client_with_id(shared_id, Some(6_011));
|
||||
let app = graph.node(
|
||||
"native-app",
|
||||
MediaRole::StreamOutput,
|
||||
NodeProps {
|
||||
client_id: Some(shared_id),
|
||||
..NodeProps::default()
|
||||
},
|
||||
);
|
||||
graph.link(app, hw);
|
||||
|
||||
// Unbounded ⇒ fails closed, exactly as before R10-3.
|
||||
assert_partition(
|
||||
&run(&graph, &ctx()),
|
||||
&[],
|
||||
&[
|
||||
("call", call, "peerspeak-owned"),
|
||||
("native-app", app, "unresolved-owner"),
|
||||
],
|
||||
);
|
||||
}
|
||||
|
||||
/// The ambiguity guard must not depend on the *first* Client claiming an id
|
||||
/// having a `sec_pid`.
|
||||
///
|
||||
/// Found by auditing R10-3 rather than by a failing case: the first cut
|
||||
/// detected a duplicate id by looking it up in the pid map, which is only
|
||||
/// populated for Clients that carry a pid at all. A pid-less Client therefore
|
||||
/// left no trace, and the next Client claiming the same id was treated as
|
||||
/// unique — resolving an ambiguous id, which is exactly the guess the guard
|
||||
/// exists to refuse. Pid-less Clients are ordinary here (`device_node`'s
|
||||
/// session client is one), so this is reachable, not theoretical.
|
||||
#[test]
|
||||
fn a_pidless_first_client_still_makes_its_id_ambiguous() {
|
||||
let mut graph = Graph::new();
|
||||
let hw = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
let call = graph.peerspeak_node("peerspeak", 7);
|
||||
graph.link(call, hw);
|
||||
let sunshine = graph.app_node("sunshine", MediaRole::StreamInput, 3_838);
|
||||
graph.link(hw, sunshine);
|
||||
|
||||
// First claimant has NO sec_pid; second has one.
|
||||
let shared_id = graph.client(None);
|
||||
graph.client_with_id(shared_id, Some(6_011));
|
||||
let app = graph.node(
|
||||
"native-app",
|
||||
MediaRole::StreamOutput,
|
||||
NodeProps {
|
||||
client_id: Some(shared_id),
|
||||
..NodeProps::default()
|
||||
},
|
||||
);
|
||||
graph.link(app, hw);
|
||||
|
||||
assert_partition(
|
||||
&run(&graph, &ctx()),
|
||||
&[],
|
||||
&[
|
||||
("call", call, "peerspeak-owned"),
|
||||
("native-app", app, "unresolved-owner"),
|
||||
],
|
||||
);
|
||||
}
|
||||
|
||||
/// A process using **two** Clients cannot escape the bridge by presenting a
|
||||
/// bogus pid on one leg and none on the other.
|
||||
///
|
||||
/// ⚠️ **This is the round-10 review's finding 1, and it was a real leak while
|
||||
/// key 4 was `node.or_else(client)`.** The node's `application.process.id` is
|
||||
/// client-controlled; the Client's `pipewire.sec.pid` is protected. Letting
|
||||
/// the node's value *replace* the Client's meant the reader was bounded by
|
||||
/// `12_345` and the output leg by `50_000`, so they shared no key, did not
|
||||
/// bridge, and — both being bounded — neither tripped the unbounded sweep.
|
||||
/// The output stayed eligible while re-emitting the call.
|
||||
///
|
||||
/// Carrying both values fixes it: the two legs share the Client pid.
|
||||
///
|
||||
/// Reachability, stated honestly: `evaluate()` today is reached only by the
|
||||
/// dry-run audit, which creates no links, so this could not echo on this
|
||||
/// branch. It becomes live the moment phase 6 consumes these decisions.
|
||||
#[test]
|
||||
fn one_process_with_two_clients_cannot_split_its_pid_to_escape_the_bridge() {
|
||||
let mut graph = Graph::new();
|
||||
let hw = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
let call = graph.peerspeak_node("peerspeak", 7);
|
||||
graph.link(call, hw);
|
||||
|
||||
// One native process, two Clients, one protected pid.
|
||||
let reader_client = graph.client(Some(50_000));
|
||||
let output_client = graph.client(Some(50_000));
|
||||
|
||||
// Its reading leg claims a pid that is not its own.
|
||||
let reader = graph.node(
|
||||
"two-client-reader",
|
||||
MediaRole::StreamInput,
|
||||
NodeProps {
|
||||
client_id: Some(reader_client),
|
||||
process_id: Some(12_345),
|
||||
..NodeProps::default()
|
||||
},
|
||||
);
|
||||
graph.link(hw, reader);
|
||||
|
||||
// Its re-emitting leg claims no pid at all.
|
||||
let output = graph.node(
|
||||
"two-client-output",
|
||||
MediaRole::StreamOutput,
|
||||
NodeProps {
|
||||
client_id: Some(output_client),
|
||||
process_id: None,
|
||||
..NodeProps::default()
|
||||
},
|
||||
);
|
||||
graph.link(output, hw);
|
||||
|
||||
// A genuinely unrelated app must survive, or "exclude everything" would
|
||||
// pass this test — the §5.1 eligible-half rule.
|
||||
let bystander = graph.app_node("mpv", MediaRole::StreamOutput, 9_001);
|
||||
graph.link(bystander, hw);
|
||||
|
||||
assert_partition(
|
||||
&run(&graph, &ctx()),
|
||||
&[("mpv", bystander)],
|
||||
&[
|
||||
("call", call, "peerspeak-owned"),
|
||||
("two-client-output", output, "tainted-owner-bridge"),
|
||||
],
|
||||
);
|
||||
}
|
||||
|
||||
/// The node's own `application.process.id` is used even when its Client's
|
||||
/// `sec_pid` is the daemon's — the single most common shape here, since a
|
||||
/// Pulse-emulated node's pid is the app's while its Client's is
|
||||
/// pipewire-pulse's.
|
||||
///
|
||||
/// ⚠️ Both values are now carried (round-10 review, finding 1), so this is no
|
||||
/// longer "the node's wins" but "exception 1 is applied per value": the
|
||||
/// daemon's `sec_pid` is dropped and the node's real pid is kept, leaving the
|
||||
/// same single key as before.
|
||||
#[test]
|
||||
fn the_nodes_own_process_id_wins_over_its_clients() {
|
||||
let mut graph = Graph::new();
|
||||
// `app_node` is exactly that shape: node pid 11_114, Client sec_pid
|
||||
// PULSE_PID. If the Client's won, exception 1 would suppress key 4 and
|
||||
// this node would be unbounded.
|
||||
let hw = graph.device_node("hw-sink", MediaRole::Sink);
|
||||
let call = graph.peerspeak_node("peerspeak", 7);
|
||||
graph.link(call, hw);
|
||||
let sunshine = graph.app_node("sunshine", MediaRole::StreamInput, 3_838);
|
||||
graph.link(hw, sunshine);
|
||||
let firefox = graph.app_node("firefox", MediaRole::StreamOutput, 11_114);
|
||||
graph.link(firefox, hw);
|
||||
|
||||
assert_partition(
|
||||
&run(&graph, &ctx()),
|
||||
&[("firefox", firefox)],
|
||||
&[("call", call, "peerspeak-owned")],
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn an_unknown_pipewire_pulse_pid_over_excludes_rather_than_leaks() {
|
||||
// v3.4 §6.1.2's failure-mode paragraph: if pixelpass cannot identify
|
||||
@@ -820,6 +1348,137 @@ fn an_ambiguous_recycled_global_id_fails_closed() {
|
||||
);
|
||||
}
|
||||
|
||||
// ──────────────────────────────────────────────────────────────────────
|
||||
// Uncertainty is not history — it never enters sticky state
|
||||
// (round 9, from a live phase-5 audit run; see `Uncertainty` in mod.rs)
|
||||
// ──────────────────────────────────────────────────────────────────────
|
||||
|
||||
#[test]
|
||||
fn unresolved_ancestry_does_not_survive_being_resolved() {
|
||||
// Measured live on a desktop: a link is observed while its output node is
|
||||
// still unbound, the input side fails closed — correctly — and then that
|
||||
// fail-closed mark became *sticky*, so a hardware sink stayed excluded for
|
||||
// the process lifetime even after the node resolved and turned out to be
|
||||
// an ordinary game. Phase 3r's bind-everything observer widens that window
|
||||
// to every node, so this must clear.
|
||||
let mut graph = Graph::new();
|
||||
let ghost = graph.dangling_id();
|
||||
let client = graph.client_of_app(6000);
|
||||
let victim = graph.node("victim-in", MediaRole::StreamInput, app(client, 6000));
|
||||
let sibling = graph.node("victim-out", MediaRole::StreamOutput, app(client, 6000));
|
||||
graph.link_ids(ghost, victim.id);
|
||||
let firefox = graph.app_node("firefox", MediaRole::StreamOutput, 11114);
|
||||
let c = ctx();
|
||||
|
||||
// While the ancestry is genuinely unresolved, the decision is unchanged:
|
||||
// fail closed, both the victim and its sibling excluded.
|
||||
let (first, sticky) = evaluate(&graph.build(), &c, &StickyState::default());
|
||||
assert_partition(
|
||||
&first,
|
||||
&[("firefox", firefox)],
|
||||
&[("victim-out", sibling, "tainted-owner-bridge")],
|
||||
);
|
||||
assert_tainted(&first, victim, "unresolved-ancestry");
|
||||
|
||||
// The node behind that id turns up — nothing tainted, it was simply not
|
||||
// observed yet. The uncertainty is gone, so nothing may remain of it.
|
||||
let late_client = graph.client_of_app(7100);
|
||||
let resolved = graph.node_with_id(
|
||||
"was-unbound",
|
||||
MediaRole::StreamOutput,
|
||||
ghost,
|
||||
app(late_client, 7100),
|
||||
);
|
||||
let (second, _) = evaluate(&graph.build(), &c, &sticky);
|
||||
assert_partition(
|
||||
&second,
|
||||
&[
|
||||
("firefox", firefox),
|
||||
("victim-out", sibling),
|
||||
("was-unbound", resolved),
|
||||
],
|
||||
&[],
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn uncertainty_laundered_into_downstream_taint_is_not_sticky_either() {
|
||||
// Retiring by reason *code* would not be enough: an unresolved node
|
||||
// propagates `tainted-upstream`, which is indistinguishable from real
|
||||
// contamination once recorded. The split has to be by provenance, so a
|
||||
// node two hops from the uncertainty must clear too.
|
||||
let mut graph = Graph::new();
|
||||
let ghost = graph.dangling_id();
|
||||
let forwarder_client = graph.client_of_app(6100);
|
||||
let forwarder_in = graph.node(
|
||||
"fwd-in",
|
||||
MediaRole::StreamInput,
|
||||
app(forwarder_client, 6100),
|
||||
);
|
||||
let forwarder_out = graph.node(
|
||||
"fwd-out",
|
||||
MediaRole::StreamOutput,
|
||||
app(forwarder_client, 6100),
|
||||
);
|
||||
let downstream_client = graph.client_of_app(6200);
|
||||
let downstream = graph.node("downstream", MediaRole::Sink, app(downstream_client, 6200));
|
||||
let downstream_leg = graph.node(
|
||||
"downstream-out",
|
||||
MediaRole::StreamOutput,
|
||||
app(downstream_client, 6200),
|
||||
);
|
||||
graph.link_ids(ghost, forwarder_in.id);
|
||||
graph.link(forwarder_out, downstream);
|
||||
let c = ctx();
|
||||
|
||||
let (first, sticky) = evaluate(&graph.build(), &c, &StickyState::default());
|
||||
assert_tainted(&first, forwarder_in, "unresolved-ancestry");
|
||||
assert_tainted(&first, downstream, "tainted-upstream");
|
||||
assert!(
|
||||
first.candidates[&downstream_leg.serial].reason().is_some(),
|
||||
"while the ancestry is unresolved the downstream owner is excluded too"
|
||||
);
|
||||
|
||||
let late_client = graph.client_of_app(7200);
|
||||
graph.node_with_id(
|
||||
"was-unbound",
|
||||
MediaRole::StreamOutput,
|
||||
ghost,
|
||||
app(late_client, 7200),
|
||||
);
|
||||
let (second, _) = evaluate(&graph.build(), &c, &sticky);
|
||||
assert_eq!(
|
||||
second.candidates[&downstream_leg.serial].reason(),
|
||||
None,
|
||||
"nothing derived from the uncertainty may outlive it"
|
||||
);
|
||||
assert_eq!(
|
||||
second.candidates[&forwarder_out.serial].reason(),
|
||||
None,
|
||||
"including the unresolved node's own owner siblings"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn real_taint_is_still_sticky_when_its_topology_goes_away() {
|
||||
// The other half of the same rule, stated positively: *evidence* is
|
||||
// history and must survive. This is the guard on the change above — if
|
||||
// provenance splitting ever leaks into the evidence path, peerspeak's own
|
||||
// audio starts escaping.
|
||||
let (graph, call, rec_in, rec_out, firefox) = sticky_scene();
|
||||
let c = ctx();
|
||||
let (_, sticky) = evaluate(&graph.build(), &c, &StickyState::default());
|
||||
let (second, _) = evaluate(&graph.build_without(&[rec_in]), &c, &sticky);
|
||||
assert_partition(
|
||||
&second,
|
||||
&[("firefox", firefox)],
|
||||
&[
|
||||
("call", call, "peerspeak-owned"),
|
||||
("rec-out", rec_out, "tainted-owner-bridge"),
|
||||
],
|
||||
);
|
||||
}
|
||||
|
||||
// ──────────────────────────────────────────────────────────────────────
|
||||
// Stickiness and lifetime-awareness (v3.4 §6.1.3)
|
||||
// ──────────────────────────────────────────────────────────────────────
|
||||
|
||||
@@ -52,6 +52,13 @@ async fn main() -> Result<()> {
|
||||
return repair::run().await;
|
||||
}
|
||||
|
||||
// Read-only diagnostic: observe the graph, report what the audio-exclusion
|
||||
// engine concludes, create nothing. Placed before the host/viewer dispatch
|
||||
// because it is neither — it shares no screen and connects to no peer.
|
||||
if cli.audit_audio {
|
||||
return host::audit::run::run_standalone().await;
|
||||
}
|
||||
|
||||
if cli.reconfigure {
|
||||
return interactive::run_reconfigure().await;
|
||||
}
|
||||
|
||||
+42
@@ -0,0 +1,42 @@
|
||||
# Screenshare audio exclusion — ownership tagging wire contract.
|
||||
#
|
||||
# peerspeak PRODUCES these carriers on every audio node it owns; pixelpass
|
||||
# CONSUMES them as the primary taint root of the exclusion engine. Neither
|
||||
# repo depends on the other, so this file is the contract: it is committed
|
||||
# byte-identical in both, and each repo has a test that asserts its own named
|
||||
# constants (and, on the producer side, the environment a real child Command
|
||||
# would carry) match these values exactly.
|
||||
#
|
||||
# peerspeak/tests/fixtures/ownership-tag-contract.txt
|
||||
# pixelpass/tests/fixtures/ownership-tag-contract.txt
|
||||
#
|
||||
# Pinned by peerspeak docs/screenshare-audio-exclusion-impl-plan.md §3 and
|
||||
# docs/screenshare-audio-exclusion-plan.md §5.1 (v3.5). Changing a value here
|
||||
# is a cross-repo breaking change: both repos must land in the same session,
|
||||
# and the phase 5 matrix must be re-run.
|
||||
#
|
||||
# Two carriers, matched as a UNION — a node is peerspeak-owned if EITHER
|
||||
# matches. Round 8 added the second because a property is invisible to the
|
||||
# PipeWire registry `global` event and readable only via a node bind, so the
|
||||
# primary taint root must not rest on one observation mechanism alone.
|
||||
|
||||
# Carrier 1 — a node property, matched EXACTLY: `prop_value` below is the
|
||||
# ONLY spelling the consumer reads as owned. A producer emitting "true", "yes"
|
||||
# or "" is NOT owned on this carrier, and only carrier 2 would still catch it.
|
||||
#
|
||||
# ⚠️ This wording is load-bearing and it CHANGED in round 10. The consumer
|
||||
# used to accept any value other than "false"/"0", on the theory that leniency
|
||||
# over-excludes and is therefore safe. It is not: leniency buys false-positive
|
||||
# exclusion, and it let any process suppress a rival application's audio from
|
||||
# the share with a property it did not even have to spell right. Fail-closed
|
||||
# on this feature is about ANCESTRY — an unresolvable graph is not eligible —
|
||||
# not about parsing.
|
||||
prop_key=peerspeak.owned
|
||||
prop_value=1
|
||||
|
||||
# Carrier 2 — a `node.name` prefix, announced by the registry without a bind.
|
||||
# `node.description` is deliberately NOT touched, so mixers still show "mpv".
|
||||
# Only the prefix is matched; the rest of the name is for diagnostics.
|
||||
node_name_prefix=peerspeak_owned_
|
||||
node_name_format=peerspeak_owned_<role>_<pid>
|
||||
node_name_example=peerspeak_owned_mpv_31284
|
||||
Reference in New Issue
Block a user